Skip to main content

CWEs that violate the OWASP API Security Top 10 standard

The following table describes which categories in the OWASP API Security Top 10 that Veracode supports for Dynamic Analysis.

CategoryDescriptionDynamic supportYears on list
API1:2023Broken Object Level AuthorizationPartial (fuzzing paths)2023
API2:2023Broken AuthenticationFull2023
API3:2023Broken Object Level Authorization*2023
API4:2023Unrestricted Resource Consumption*2023
API5:2023Broken Function Level Authorization*2023
API6:2023Unrestricted Access to Sensitive Business Flows*2023
API7:2023Server Side Request ForgeryFull2023
API8:2023Security MisconfigurationFull2023
API9:2023Improper Inventory ManagementPartial2023
API10:2023Unsafe Consumption of APIs*2023
  • Dynamic Analysis might provide inaccurate results for these categories. For accurate results, we recommend testing these categories with Manual Penetration Testing (MPT).