Skip to main content

Findings detected by DAST

This section lists the Common Weakness Enumerations (CWEs) for findings (flaws) detected by Veracode DAST. To map the findings found during scanning, we reference the CWE standard.

Since its founding, Veracode has reported findings using the industry standard Common Weakness Enumeration as a taxonomy. The CWE provides a mapping of all known types of software weakness or vulnerability, and provides supplemental information to help developers understand the cause of common weaknesses and how to fix them. Veracode always uses the latest version of the CWE, and updates to new versions within 90 days of release.

For a complete list of CWEs detected by Veracode Static Analysis, see Findings detected by SAST. Veracode Manual Penetration Testing scans might report any valid CWE. You can see the full list of CWEs at the Mitre CWE website.

The listed findings are grouped according to a list of categories that Veracode uses for convenience. The categories generally correspond to common types of attacks.

In the Veracode Platform, on the Triage Flaws page, the Flaw severity column indicates the finding severities using Veracode's severity scale.

CWEs that violate security standards provides the full list of CWEs that can prevent an application from passing policy based on the Security Standard policy rule.

Authentication Issues

CWE IDCWE nameSeverity
287Improper Authentication4
352Cross-Site Request Forgery (CSRF)3

Authorization Issues

CWE IDCWE nameSeverity
862Missing Authorization2

Code Injection

CWE IDCWE nameSeverity
74Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)4
91XML Injection (Blind XPath Injection)3
95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')5
98Improper Control of Filename for Include/Require Statement in PHP Program (PHP File Inclusion)4
830Inclusion of Web Functionality from an Untrusted Source2

Code Quality

CWE IDCWE nameSeverity
477Use of Obsolete Functions0

Command or Argument Injection

CWE IDCWE nameSeverity
78Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)5

Credentials Management

CWE IDCWE nameSeverity
259Use of Hard-coded Password3
522Insufficiently Protected Credentials3

CRLF Injection

CWE IDCWE NameSeverity
113Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Response Splitting)3

Cross-Site Scripting (XSS)

CWE IDCWE nameSeverity
79Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)3
80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)3
83Improper Neutralization of Script in Attributes in a Web Page3

Cryptographic Issues

CWE IDCWE nameSeverity
296Improper Following of Chain of Trust for Certificate Validation3
297Improper Validation of Host-specific Certificate Data3
298Improper Validation of Certificate Expiration3
299Improper Check for Certificate Revocation3
321Use of Hard-coded Cryptographic Key3
325Missing Cryptographic Step3
326Inadequate Encryption Strength3
327Use of a Broken or Risky Cryptographic Algorithm3
345Insufficient Verification of Data Authenticity4
614Sensitive Cookie in HTTPS Session Without Secure Attribute2

Deployment Configuration

CWE IDCWE nameSeverity
402Transmission of Private Resources into a New Sphere (Resource Leak)3
668Exposure of Resource to Wrong Sphere3

Directory Traversal

CWE IDCWE nameSeverity
22Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)3

Encapsulation

CWE IDCWE nameSeverity
502Deserialization of Untrusted Data3
693Protection Mechanism Failure3

Information Leakage

CWE IDCWE NameSeverity
200Information Exposure2
209Information Exposure Through an Error Message2
215Information Exposure Through Debug Information2
359Exposure of Private Information (Privacy Violation)2
526Information Exposure Through Environmental Variables2
530Exposure of Backup File to an Unauthorized Control Sphere2
538File and Directory Information Exposure2
548Information Exposure Through Directory Listing2
611Information Exposure Through XML External Entity Reference3
918Server-side Request Forgery3

Insecure Dependencies

CWE IDCWE nameSeverity
829Inclusion of Functionality from Untrusted Control Sphere3
1357Reliance on Insufficiently Trustworthy Component3

Insufficient Input Validation

CWE IDCWE nameSeverity
115Misinterpretation of Input4
434Unrestricted Upload of File with Dangerous Type4
601URL Redirection to Untrusted Site (Open Redirect)3

Server Configuration

CWE IDCWE nameSeverity
16Configuration0
642External Control of Critical State Data2
757Selection of Less-Secure Algorithm During Negotiation (Algorithm Downgrade)3
1125Excessive Attack Surface0

Session Fixation

CWE IDCWE nameSeverity
384Session Fixation3

SQL Injection

CWE IDCWE nameSeverity
89Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)4
943Improper Neutralization of Special Elements in Data Query Logic4