CWE WEAKNESSES / CWE-669
CWE-669
Incorrect Resource Transfer Between Spheres
Class
What it is
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Impact
| Confidentiality, Integrity | Read Application Data, Modify Application Data, Unexpected State |
Real-world CVE examples
- CVE-2021-22909 — Chain: router's firmware update procedure uses curl with "-k" (insecure) option that disables certificate validation (CWE-295), allowing adversary-in-the-middle
- CVE-2023-5227 — PHP-based FAQ management app does not check the MIME type for uploaded images
- CVE-2005-0406 — Some image editors modify a JPEG image, but the original EXIF thumbnail image is left intact within the JPEG. (Also an interaction error).
Related weaknesses
Test & detect
Browse all common weaknesses, check related exploited CVEs, or map to ATT&CK techniques.
Source: MITRE CWE. View on cwe.mitre.org →