VYPR

CWE-105

Struts: Form Field Without Validator

VariantDraft

Description

The product has a form field that is not validated by a corresponding validation form, which can introduce other weaknesses related to insufficient input validation.

Omitting validation for even a single input field may give attackers the leeway they need to compromise the product. Although J2EE applications are not generally susceptible to memory corruption attacks, if a J2EE application interfaces with native code that does not perform array bounds checking, an attacker may be able to use an input validation mistake in the J2EE application to launch a buffer overflow attack.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (0)

No CVEs match the current filter.