Skip to main content

CWEs detected as flaws

This section lists the Common Weakness Enumerations (CWEs) that we search for during Veracode Static Analysis (SAST) or Veracode DAST scans. To map the findings (flaws) found during these scans, Veracode references the CWE standard.

Since its founding, Veracode has reported flaws using the industry standard Common Weakness Enumeration as a taxonomy. The CWE provides a mapping of all known types of software weakness or vulnerability, and provides supplemental information to help developers understand the cause of common weaknesses and how to fix them. Veracode always uses the latest version of the CWE, and updates to new versions within 90 days of release. This page lists the flaws that Veracode might report in automated SAST and DAST scans. If a flaw maps to several CWEs, Veracode generally reports the most general CWE that describes that particular case. For example, Veracode prefers CWE-80 for cross-site scripting over its child CWEs. Veracode updates this list frequently.

Veracode Manual Penetration Testing scans might report any valid CWE. You can see the full list of CWEs at the Mitre CWE website.

The listed flaws are grouped according to a list of categories that Veracode uses for convenience. The categories generally correspond to common types of attacks.

In the Veracode Platform, on the Triage Flaws page, the Flaw severity column indicates the flaw severities using Veracode's severity scale.

CWEs that violate security standards provides the full list of CWEs that can prevent an application from passing policy based on the Security Standard policy rule.

API Abuse

CWE IDCWE nameFlaw severitySAST supportDAST support
234Failure to Handle Missing Parameter3YesNo
243Creation of Chroot Jail Without Changing Working Directory4YesNo
245J2EE Bad Practices: Direct Management of Connections2YesNo
560Use of Umask() with Chmod-Style Argument3YesNo
628Function Call with Incorrectly Specified Arguments2YesNo
675Duplicate Operations on Resource2YesNo

Authentication Issues

CWE IDCWE nameFlaw severitySAST supportDAST support
284Improper Access Control3YesNo
287Improper Authentication4YesYes
350Reliance on Reverse DNS Resolution for a Security-Critical Action3YesNo
352Cross-Site Request Forgery (CSRF)3YesYes
923Improper Restriction of Communication Channel to Intended Endpoints3YesNo

Authorization Issues

CWE IDCWE nameFlaw severitySAST supportDAST support
99Improper Control of Resource Identifiers3YesNo
272Least Privilege Violation3YesNo
273Improper Check for Dropped Privileges3YesNo
274Improper Handling of Insufficient Privileges0YesNo
282Improper Ownership Management3YesNo
285Improper Authorization3YesNo
346Origin Validation Error3YesNo
451User Interface (UI) Misrepresentation of Critical Information3YesNo
566Authorization Bypass Through User-Controlled SQL Primary Key3YesNo
639Authorization Bypass Through User-Controlled Key4YesNo
708Incorrect Ownership Assignment4YesNo
732Incorrect Permission Assignment for Critical Resource3YesNo
862Missing Authorization2NoYes
942Permissive Cross-domain Policy with Untrusted Domains3YesNo

Buffer Management Errors

CWE IDCWE nameFlaw severitySAST supportDAST support
118Improper Access of Indexable Resource (Range Error)3YesNo
125Out-of-Bounds Read3YesNo
129Improper Validation of Array Index3YesNo
135Incorrect Calculation of Multi-Byte String Length5YesNo
170Improper Null Termination3YesNo
193Off-by-One Error3YesNo
787Out-of-Bounds Write3YesNo
823Use of Out-of-Range Pointer Offset3YesNo
824Access of Uninitialized Pointer3YesNo

Buffer Overflow

CWE IDCWE nameFlaw severitySAST supportDAST support
121Stack-Based Buffer Overflow5YesNo

Code Injection

CWE IDCWE nameFlaw severitySAST supportDAST support
74Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)4NoYes
91XML Injection (Blind XPath Injection)3YesYes
94Improper Control of Generation of Code3YesNo
95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')5YesYes
98Improper Control of Filename for Include/Require Statement in PHP Program (PHP File Inclusion)4YesYes
185Incorrect Regular Expression2YesNo
830Inclusion of Web Functionality from an Untrusted Source2NoYes
1336Improper Neutralization of Special Elements Used in a Template Engine5YesNo

Code Quality

CWE IDCWE nameFlaw severitySAST supportDAST support
111Direct Use of Unsafe JNI4YesNo
159Failure to Sanitize Special Element0YesNo
401Improper Release of Memory Before Removing Last Reference (Memory Leak)2YesNo
404Improper Resource Shutdown or Release0YesNo
415Double Free3YesNo
416Use After Free2YesNo
477Use of Obsolete Functions0YesYes
479Signal Handler Use of a Non-Reentrant Function3YesNo
489Leftover Debug Code3YesNo
597Use of Wrong Operator in String Comparison2YesNo

Command or Argument Injection

CWE IDCWE nameFlaw severitySAST supportDAST support
77Improper Neutralization of Special Elements used in a Command (Command Injection)5YesNo
78Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)5YesYes
88Argument Injection or Modification3YesNo

Credentials Management

CWE IDCWE nameFlaw severitySAST supportDAST support
256Plaintext Storage of a Password3YesNo
258Empty Password in Configuration File3YesNo
259Use of Hard-coded Password3YesYes
522Insufficiently Protected Credentials3YesYes
798Use of Hard-code Credentials3YesNo

CRLF Injection

CWE IDCWE nameFlaw severitySAST supportDAST support
93Improper Neutralization of CRLF Sequences (CRLF Injection)3YesNo
113Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Response Splitting)3YesYes
117Improper Output Neutralization for Logs3YesNo

Cross-Site Scripting (XSS)

CWE IDCWE nameFlaw severitySAST supportDAST support
79Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)3YesYes
80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)3YesYes
83Improper Neutralization of Script in Attributes in a Web Page3NoYes
86Improper Neutralization of Invalid Characters in Identifiers in Web Pages3YesNo

Cryptographic Issues

CWE IDCWE nameFlaw severitySAST supportDAST support
261Weak Cryptography for Passwords3YesNo
295Improper Certificate Validation3YesNo
296Improper Following of Chain of Trust for Certificate Validation3NoYes
297Improper Validation of Host-specific Certificate Data3YesYes
298Improper Validation of Certificate Expiration3NoYes
299Improper Check for Certificate Revocation3NoYes
311Missing Encryption of Sensitive Data3YesNo
312Cleartext Storage of Sensitive Information3YesNo
313Plaintext Storage in a File or on Disk3YesNo
316Plaintext Storage in Memory3YesNo
319Cleartext Transmission of Sensitive Information3YesNo
321Use of Hard-coded Cryptographic Key3YesYes
325Missing Cryptographic Step3NoYes
326Inadequate Encryption Strength3YesYes
327Use of a Broken or Risky Cryptographic Algorithm3YesYes
329Not Using a Random IV with CBC Mode2YesNo
330Use of Insufficiently Random Values3YesNo
331Insufficient Entropy3YesNo
338Use of Cryptographically Weak Pseudo-Random Number Generator3YesNo
345Insufficient Verification of Data Authenticity4YesYes
347Improper Verification of Cryptographic Signature2YesNo
354Improper Validation of Integrity Check Value3YesNo
547Use of Hard-coded, Security-relevant Constants3YesNo
614Sensitive Cookie in HTTPS Session Without Secure Attribute2YesYes
760Use of a One-Way Hash with a Predictable Salt3YesNo
780Use of RSA without Optimal Asymmetric Encryption Padding3YesNo
916Use of Password Hash With Insufficient Computational Effort3YesNo

Dangerous Functions

CWE IDCWE nameFlaw severitySAST supportDAST support
242Use of Inherently Dangerous Function5YesNo
676Use of Potentially Dangerous Function3YesNo

Deployment Configuration

CWE IDCWE nameFlaw severitySAST supportDAST support
402Transmission of Private Resources into a New Sphere (Resource Leak)3NoYes
668Exposure of Resource to Wrong Sphere3YesYes
926Improper Export of Android Application Components3YesNo

Directory Traversal

CWE IDCWE nameFlaw severitySAST supportDAST support
22Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)3YesYes
73External Control of File Name or Path3YesNo

Encapsulation

CWE IDCWE nameFlaw severitySAST supportDAST support
501Trust Boundary Violation0YesNo
502Deserialization of Untrusted Data3YesYes
693Protection Mechanism Failure3YesYes
749Exposed Dangerous Method or Function4YesNo

Error Handling

CWE IDCWE nameFlaw severitySAST supportDAST support
248Uncaught Exception2YesNo
252Unchecked Return Value2YesNo

Format String

CWE IDCWE nameFlaw severitySAST supportDAST support
134Use of Externally-Controlled Format String5YesNo

Information Leakage

CWE IDCWE nameFlaw severitySAST supportDAST support
200Information Exposure2YesYes
201Insertion of Sensitive Information Into Sent Data2YesNo
209Information Exposure Through an Error Message2YesYes
215Information Exposure Through Debug Information2YesYes
359Exposure of Private Information (Privacy Violation)2YesYes
497Exposure of System Data to an Unauthorized Control Sphere2YesNo
526Information Exposure Through Environmental Variables2NoYes
530Exposure of Backup File to an Unauthorized Control Sphere2NoYes
532Insertion of Sensitive Information into Log File2YesNo
538File and Directory Information Exposure2NoYes
548Information Exposure Through Directory Listing2NoYes
611Information Exposure Through XML External Entity Reference3YesYes
615Information Exposure Through Comments2YesNo
665Improper Initialization2YesNo
918Server-side Request Forgery3YesYes

Insecure Dependencies

CWE IDCWE nameFlaw severitySAST supportDAST support
829Inclusion of Functionality from Untrusted Control Sphere3YesYes
1357Reliance on Insufficiently Trustworthy Component3NoYes

Insufficient Input Validation

CWE IDCWE nameFlaw severitySAST supportDAST support
20Improper Input Validation0YesNo
90Improper Neutralization of Special Elements Used in an LDAP Query (LDAP Injection)3YesNo
103Struts: Incomplete validate() Method Definition3YesNo
104Struts: Form Bean Does Not Extend Validation Class3YesNo
112Missing XML Validation3YesNo
115Misinterpretation of Input4NoYes
183Permissive List of Allowed Inputs3YesNo
223Omission of Security-relevant Information2YesNo
434Unrestricted Upload of File with Dangerous Type4NoYes
470Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection)3YesNo
472External Control of Assumed-Immutable Web Parameter3YesNo
601URL Redirection to Untrusted Site (Open Redirect)3YesYes
618Exposed Unsafe ActiveX Method5YesNo
915Improperly Controlled Modification of Dynamically-Determined Object Attributes3YesNo
1174ASP.NET Misconfiguration: Improper Model Validation2YesNo
1236Improper Neutralization of Formula Elements in a CSV File3YesNo
1427Improper Neutralization of Input Used for LLM Prompting4YesNo

Numeric Errors

CWE IDCWE nameFlaw severitySAST supportDAST support
190Integer Overflow or Wraparound5YesNo
191Integer Underflow (Wrap or Wraparound)3YesNo
192Integer Coercion Error3YesNo
195Signed to Unsigned Conversion Error3YesNo
196Unsigned to Signed Conversion Error3YesNo
197Numeric Truncation Error3YesNo

Potential Backdoor

CWE IDCWE nameFlaw severitySAST supportDAST support
398Indicator of Poor Code Quality0YesNo
506Embedded Malicious Code4YesNo
511Logic/Time Bomb5YesNo
514Covert Channel2YesNo
656Reliance on Security Through Obscurity0YesNo

Race Conditions

CWE IDCWE nameFlaw severitySAST supportDAST support
366Race Condition within a Thread3YesNo
367Time-of-check Time-of-use (TOCTOU) Race Condition3YesNo
421Race Condition During Access to Alternate Channel3YesNo

Server Configuration

CWE IDCWE nameFlaw severitySAST supportDAST support
16Configuration0NoYes
441Unintended Proxy or Intermediary (Confused Deputy)3YesNo
642External Control of Critical State Data2NoYes
757Selection of Less-Secure Algorithm During Negotiation (Algorithm Downgrade)3YesYes
1125Excessive Attack Surface0NoYes

Session Fixation

CWE IDCWE nameFlaw severityStatic supportDynamic support
384Session Fixation3YesYes

SQL Injection

CWE IDCWE nameFlaw severitySAST supportDAST support
89Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)4YesYes
564SQL Injection: Hibernate4YesNo
943Improper Neutralization of Special Elements in Data Query Logic4YesYes

Time and State

CWE IDCWE nameFlaw severitySAST supportDAST support
377Insecure Temporary File3YesNo
382J2EE Bad Practices: Use of System.exit()2YesNo
557Concurrency Issues2YesNo
691Insufficient Control Flow Management0YesNo

Untrusted Initialization

CWE IDCWE nameFlaw severitySAST supportDAST support
15External Control of System or Configuration Setting4YesNo
454External Initialization of Trusted Variables or Data Stores0YesNo

Untrusted Search Path

CWE IDCWE nameFlaw severitySAST supportDAST support
114Process Control5YesNo
426Untrusted Search Path3YesNo
427Uncontrolled Search Path Element3YesNo