CWE-1084: Invokable Control Element with Excessive File or Data Access Operations

ID CWE-1084
Abstraction Base
Structure Simple
Status Incomplete
A function or method contains too many operations that utilize a data manager or file resource.

This issue makes it more difficult to maintain the product, which indirectly affects security by making it more difficult or time-consuming to find and/or fix vulnerabilities. It also might make it easier to introduce vulnerabilities.

While the interpretation of "too many operations" may vary for each product or developer, CISQ recommends a default maximum of 7 operations for the same data manager or file.

Relationships

View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-405 Asymmetric Resource Consumption (Amplification) Class Simple Incomplete
Loading...
Loading...