CWE-766: Critical Data Element Declared Public

ID CWE-766
Abstraction Base
Structure Simple
Status Incomplete
The product declares a critical variable, field, or member to be public when intended security policy requires it to be private.

This issue makes it more difficult to maintain the product, which indirectly affects security by making it more difficult or time-consuming to find and/or fix vulnerabilities. It also might make it easier to introduce vulnerabilities.

Modes of Introduction

Phase Note
Implementation

Applicable Platforms

Type Class Name Prevalence
Language C++
Language C#
Language Java

Relationships

View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-732 Incorrect Permission Assignment for Critical Resource Class Simple Draft
CWE-1000 Research Concepts Draft CWE-1061 Insufficient Encapsulation Class Simple Incomplete
Loading...
Loading...