This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Pages that link to "Category:Technical Impact"
The following pages link to Category:Technical Impact:
View (previous 50 | next 50) (20 | 50 | 100 | 250 | 500)- Template:Technical Impact β (β links)
- Technical Impact template β (β links)
- Technical Impacts (redirect page) β (β links)
- Injection problem β (β links)
- Time of check, time of use race condition β (β links)
- Race condition in switch β (β links)
- Race condition in signal handler β (β links)
- Race condition in checking for certificate revocation β (β links)
- Race condition within a thread β (β links)
- Using a broken or risky cryptographic algorithm β (β links)
- Unprotected Alternate Channel β (β links)
- Business logic vulnerability β (β links)
- CRLF Injection β (β links)
- Catch NullPointerException β (β links)
- Channel and Path Errors β (β links)
- Cleansing, Canonicalization, and Comparison Errors β (β links)
- Collapse of Data into Unsafe Value β (β links)
- Context Switching Race Condition β (β links)
- Common Special Element Manipulations β (β links)
- Cross-Boundary Cleansing Infoleak β (β links)
- Dangerous handler not cleared/disabled during sensitive operations β (β links)
- Data Amplification β (β links)
- Data Leaking Between Users β (β links)
- Data Structure Issues β (β links)
- Delimiter Problems β (β links)
- Delimiter between Expressions or Commands β (β links)
- Directory Restriction Error β (β links)
- Discrepancy Information Leaks β (β links)
- Doubled character XSS manipulations β (β links)
- Early Amplification β (β links)
- Empty String Password β (β links)
- Error Conditions, Return Values, Status Codes β (β links)
- Error Message Infoleaks β (β links)
- Escape, Meta, or Control Character / Sequence β (β links)
- Expected behavior violation β (β links)
- Improper Null Termination β (β links)
- Improper resource shutdown or release β (β links)
- Improperly Implemented Security Check for Standard β (β links)
- Improperly Trusted Reverse DNS β (β links)
- Improperly Verified Signature β (β links)
- Incomplete Cleanup β (β links)
- Incomplete Element β (β links)
- Incomplete Internal State Distinction β (β links)
- Inconsistent Elements β (β links)
- Inconsistent Implementations β (β links)
- Inconsistent Special Elements β (β links)
- Incorrect Privilege Assignment β (β links)
- Incorrect initialization β (β links)
- Infoleak Using Debug Information β (β links)
- Information Leak (information disclosure) β (β links)
- Information loss or omission β (β links)
- Initialization and Cleanup Errors β (β links)
- Input Terminator β (β links)
- Insecure Compiler Optimization β (β links)
- Insecure Default Permissions β (β links)
- Insecure Temporary File β (β links)
- Insecure default variable initialization β (β links)
- Insecure execution-assigned permissions β (β links)
- Insecure inherited permissions β (β links)
- Insecure preserved inherited permissions β (β links)
- Installation Issues β (β links)
- Insufficient Entropy β (β links)
- Insufficient Resource Locking β (β links)
- Insufficient Resource Pool β (β links)
- Insufficient privileges β (β links)
- J2EE Bad Practices: Sockets β (β links)
- J2EE Bad Practices: System.exit() β (β links)
- J2EE Bad Practices: Threads β (β links)
- J2EE Bad Practices: getConnection() β (β links)
- Insecure Transport β (β links)
- Insufficient Session-ID Length β (β links)
- Missing Error Handling β (β links)
- J2EE Misconfiguration: Weak Access Permissions β (β links)
- J2EE Time and State Issues β (β links)
- Least Privilege Violation β (β links)
- Leftover Debug Code β (β links)
- Mac virtual file problems β (β links)
- Memory leak β (β links)
- Misinterpretation error β (β links)
- Missing access control β (β links)
- Missing critical step in authentication β (β links)
- Missing element error β (β links)
- Missing error status code β (β links)
- Missing handler β (β links)
- Missing initialization β (β links)
- Missing lock check β (β links)
- Missing required cryptographic step β (β links)
- Missing special element β (β links)
- Missing value error β (β links)
- Mixed encoding β (β links)
- Modification of assumed-immutable data β (β links)
- Multiple failed authentication attempts not prevented β (β links)
- Multiple internal special element β (β links)
- Multiple interpretation error (MIE) β (β links)
- Multiple interpretations of UI input β (β links)
- Multiple Leading Special Elements β (β links)
- Multiple Trailing Special Elements β (β links)
- Mutable objects passed by reference β (β links)
- No authentication for critical function β (β links)
- Obscured Security-relevant Information by Alternate Name β (β links)
- Obsolete feature in UI β (β links)
- Off-by-one Error β (β links)
- Often Misused: Path Manipulation β (β links)
- Omission of Security-relevant Information β (β links)
- Origin Validation Error β (β links)
- Other length calculation error β (β links)
- Out-of-bounds Read β (β links)
- Overly Restrictive Regular Expression β (β links)
- Ownership errors β (β links)
- PHP External Variable Modification β (β links)
- PHP File Inclusion β (β links)
- PRNG Seed Error β (β links)
- Parameter Problems β (β links)
- Partial Comparison β (β links)
- Patch Issues β (β links)
- Path Equivalence β (β links)
- Path Issue - Windows 8.3 Filename β (β links)
- Path Issue - Windows UNC share - '/UNC/share/name/' β (β links)
- Path Issue - asterisk wildcard - filedir* β (β links)
- Path Issue - backslash absolute path - /absolute/pathname/here β (β links)
- Path Issue - directory doubled dot dot backslash β (β links)
- Path Issue - directory doubled dot dot slash β (β links)
- Path Issue - dirname/fakechild/ β (β links)
- Path Issue - dot dot backslash β (β links)
- Path Issue - doubled dot dot slash β (β links)
- Path Issue - doubled triple dot slash β (β links)
- Path Issue - drive letter or Windows volume - 'C:dirname' β (β links)
- Path Issue - internal dot - 'file.ordir' β (β links)
- Path Issue - internal space - file(SPACE)name β (β links)
- Path Issue - leading directory dot dot backslash β (β links)
- Path Issue - leading directory dot dot slash β (β links)
- Path Issue - leading dot dot backslash β (β links)
- Path Issue - leading dot dot slash β (β links)
- Path Issue - leading space β (β links)
- Path Issue - multiple dot β (β links)
- Path Issue - multiple internal backslash β (β links)
- Path Issue - multiple leading slash β (β links)
- Path Issue - multiple trailing dot β (β links)
- Path Issue - multiple trailing slash β (β links)
- Path Issue - single dot directory β (β links)
- Path Issue - slash absolute path β (β links)
- Path Issue - trailing backslash β (β links)
- Path Issue - trailing dot β (β links)
- Path Issue - trailing slash β (β links)
- Path Issue - trailing space β (β links)
- Path Issue - triple dot β (β links)
- Pathname Traversal and Equivalence Errors β (β links)
- Permission errors β (β links)
- Permission preservation failure β (β links)
- Permissions, Privileges, and ACLs β (β links)
- Permissive Whitelist β (β links)
- Password Plaintext Storage β (β links)
- Plaintext Storage in Cookie β (β links)
- Plaintext Storage in Executable β (β links)
- Plaintext Storage in File or on Disk β (β links)
- Plaintext Storage in GUI β (β links)
- Plaintext Storage in Memory β (β links)
- Plaintext Storage of Sensitive Information β (β links)
- Pointer Issues β (β links)
- Porting Issues β (β links)
- Predictability problems β (β links)
- Predictable Exact Value from Previous Values β (β links)
- Predictable Seed in PRNG β (β links)
- Predictable Value Range from Previous Values β (β links)
- Predictable from Observable State β (β links)
- Private Array-Typed Field Returned From A Public Method β (β links)
- Privilege / sandbox errors β (β links)
- Privilege Chaining β (β links)
- Privilege Context Switching Error β (β links)
- Privilege Dropping / Lowering Errors β (β links)
- Privilege Management Error β (β links)
- Process Control β (β links)
- Process information infoleak to other processes β (β links)
- Product UI does not warn user of unsafe actions β (β links)
- Product-External Error Message Infoleak β (β links)
- Product-Generated Error Message Infoleak β (β links)
- Proxied Trusted Channel β (β links)
- Public Data Assigned to Private Array-Typed Field β (β links)
- Race condition enabling link following β (β links)
- Randomness and Predictability β (β links)
- Record Delimiter β (β links)
- Regular Expression Error β (β links)
- Representation Errors β (β links)
- Requirements Issues β (β links)
- Resource Locking problems β (β links)
- Resource Management Errors β (β links)
- Resource leaks β (β links)
- Response discrepancy infoleak β (β links)
- Reversible One-Way Hash β (β links)
- Sensitive Data Under Web Root β (β links)
- Sensitive Information Uncleared Before Use β (β links)
- Signal Errors β (β links)
- Small Seed Space in PRNG β (β links)
- Small Space of Random Values β (β links)
- Static Value in Unpredictable Context β (β links)
- Improper Data Validation β (β links)
- Struts: Erroneous validate() Method β (β links)
- Struts: Form Bean Does Not Extend Validation Class β (β links)
- Struts: Form Field Without Validator β (β links)
- Struts: Plug-in Framework Not In Use β (β links)
- Struts: Unused Validation Form β (β links)
- Struts: Unvalidated Action Form β (β links)
- Struts: Validator Turned Off β (β links)
- Struts: Validator Without Form Field β (β links)
- Substitution Character β (β links)
- System Configuration Issues β (β links)
- System Operations Issues β (β links)
- Technology-Specific Input Validation Problems β (β links)
- Technology-Specific Special Elements β (β links)
- Technology-Specific Time and State Issues β (β links)
- Technology-specific Environment Issues β (β links)
- Temporary File Issues β (β links)
- Testing Issues β (β links)
- The UI performs the wrong action β (β links)
- Time and State β (β links)
- Time of Introduction β (β links)
- Time-of-check Time-of-use race condition β (β links)
- Timing discrepancy infoleak β (β links)
- Trailing Special Element β (β links)
- Trapdoor β (β links)
- Truncation of Security-relevant Information β (β links)
- UI Misrepresentation of Critical Information β (β links)
- UNIX Path Link problems β (β links)
- UNIX file descriptor leak β (β links)
- UNIX hard link β (β links)
- UNIX symbolic link (symlink) following β (β links)
- URL Encoding (Hex Encoding) β (β links)
- Uncontrolled Search Path Element β (β links)
- Undefined Behavior β (β links)
- Undefined Parameter Error β (β links)
- Undefined Value Error β (β links)
- Unexpected Status Code or Return Value β (β links)
- Unimplemented or unsupported feature in UI β (β links)
- Unintended proxy/intermediary β (β links)
- Unparsed Raw Web Content Delivery β (β links)
- Unprotected Primary Channel β (β links)
- Unquoted Search Path or Element β (β links)
- Unrestricted Critical Resource Lock β (β links)
- Unrestricted File Upload β (β links)
- Unsafe JNI β (β links)
- Unsafe Privilege β (β links)
- Unsafe use of Reflection β (β links)
- Untrusted Data Appended with Trusted Data β (β links)
- Unverified Ownership β (β links)
- Use of Less Trusted Source β (β links)
- User Interface Quality Errors β (β links)
- User Interface Security Errors β (β links)
- User interface inconsistency β (β links)
- User management errors β (β links)
- Validate-Before-Canonicalize β (β links)
- Validate-Before-Filter β (β links)
- Value Delimiter β (β links)
- Value Problems β (β links)
- Variable Name Delimiter β (β links)
- Virtual Files β (β links)
- Weak Encryption β (β links)
- Wrong Data Type β (β links)
- Wrong Status Code β (β links)
- Code Correctness: Call to Thread.run() β (β links)
- Code Correctness: Call to System.gc() β (β links)
- Code Correctness: Erroneous finalize() Method β (β links)
- EJB Bad Practices: Use of AWT/Swing β (β links)
- EJB Bad Practices: Use of Class Loader β (β links)
- EJB Bad Practices: Use of java.io β (β links)
- EJB Bad Practices: Use of Sockets β (β links)
- EJB Bad Practices: Use of Synchronization Primitives β (β links)
- Poor Style: Explicit call to finalize() β (β links)
- Password Management: Hardcoded Password β (β links)
- Code Correctness: Double-Checked Locking β (β links)
- Return Inside Finally Block β (β links)
- Code Correctness: Class Does Not Implement Cloneable β (β links)
- Code Correctness: Erroneous String Compare β (β links)
- Code Correctness: Misspelled Method Name β (β links)
- Code Correctness: null Argument to equals() β (β links)
- Dead Code: Broken Override β (β links)
- Dead Code: Expression is Always False β (β links)
- Dead Code: Expression is Always True β (β links)
- Dead Code: Unused Field β (β links)
- Dead Code: Unused Method β (β links)
- Poor Style: Confusing Naming β (β links)
- Poor Style: Empty Synchronized Block β (β links)
- Poor Style: Identifier Contains Dollar Symbol ($) β (β links)
- Portability Flaw β (β links)
- Poor Logging Practice β (β links)
- Poor Logging Practice: Multiple Loggers β (β links)
- Poor Logging Practice: Use of a System Output Stream β (β links)
- System Information Leak: Missing Catch Block β (β links)
- Unsafe Mobile Code β (β links)
- Unsafe Mobile Code: Inner Class β (β links)
- Unsafe Mobile Code: Public finalize() Method β (β links)
- Unsafe Mobile Code: Dangerous Array Declaration β (β links)
- Unsafe Mobile Code: Dangerous Public Field β (β links)
- Missing XML Validation β (β links)
- String Termination Error β (β links)
- Struts: Form Does Not Extend Validation Class β (β links)
- Unchecked Return Value: Missing Check against Null β (β links)
- Weak credentials β (β links)
- J2EE Bad Practices: JSP Expressions β (β links)
- Vulnerability template β (β links)
- Business Impact template β (β links)
- Losing customers β (β links)
- Damage to brand β (β links)
- Loss of customerβs trust β (β links)
- Lawsuit β (β links)
- Legal costs associated with breach β (β links)
- Criminal and civil judgments β (β links)
- Financial penalties β (β links)
- Censure by regulating agency β (β links)
- Release of a single personβs information β (β links)
- Mass release of peopleβs information β (β links)
- Loss of employee information β (β links)
- Loss of financial information β (β links)
- Loss of healthcare information β (β links)
- Loss of video rental information β (β links)
- Expression Language Injection β (β links)
- Anti CSRF Tokens ASP.NET β (β links)
- Windows Identity Foundation β (β links)
- DPAPI β (β links)
- .NET Callbacks - Vulnerabilities and Remediation β (β links)
- Dependency Injection β (β links)
- IoC containers β (β links)
- ASP.NET Identity β (β links)
- .NET Memory Management β (β links)
- Preventing SQL Injection in ADO.NET β (β links)
- Authenticated Symmetric Encryption in .NET β (β links)
- Information exposure through query strings in url β (β links)
- Category:Business Impact β (β links)
- Technical Impact (redirect page) β (β links)
- Technical Impact template β (β links)
- Loss of confidentiality β (β links)
- Loss of integrity β (β links)
- Loss of availability β (β links)
- Loss of accountability β (β links)
- OWASP Summer of Code 2008 Applications β (β links)
- OWASP Summer of Code 2008 Applications - for majority vote β (β links)
- Loss of confidentiality β (β links)
- Loss of integrity β (β links)
- Loss of availability β (β links)
- Loss of accountability β (β links)