Common Weakness Enumeration (CWE™)

Quality Clouds' rules are based on and link to industry standards. CWE is one of these standards in the area of security.

About CWE

Common Weakness Enumeration (CWE™) is a community-developed list of common software and hardware weakness types that have security ramifications. 

Weaknesses are flaws, faults, bugs, vulnerabilities, or other errors in software or hardware implementation, code, design, or architecture that if left unaddressed could result in systems, networks, or hardware being vulnerable to attack. 

The CWE List and associated classification taxonomy serve as a language that can be used to identify and describe these weaknesses in terms of CWEs.


CWE in Quality Clouds rules

Quality Clouds security rules link to the following CWE weaknesses:

CWE IDTitleQuality Clouds rules
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Salesforce:

CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection)

Salesforce:

ServiceNow:

CWE-150Improper Neutralization of Escape

ServiceNow:

CWE-259Use of Hard-coded Password

Salesforce

ServiceNow:

CWE-284Improper Access Control

Salesforce

ServiceNow:

CWE-311Missing Encryption of Sensitive Data

Salesforce: 

ServiceNow:

CWE-327Use of a Broken or Risky Cryptographic Algorithm

ServiceNow:

CWE-352Cross-Site Request Forgery (CSRF)

Salesforce: 

CWE-477Use of Obsolete Function
CWE-489Leftover Debug Code

ServiceNow:

CWE-512Spyware

Salesforce:

ServiceNow:

CWE-521Weak Password Requirements

Salesforce:

CWE-525Use of Web Browser Cache Containing Sensitive Information.

ServiceNow:

CWE-539Information Exposure Through Persistent cookies

ServiceNow:

CWE-613Insufficient Session Expiration

Salesforce:

CWE-862Missing Authorization

ServiceNow:

CWE-1004Sensitive Cookie Without HttpOnly Flag

ServiceNow:

CWE-1021Improper Restriction of Rendered UI Layers or Frames

Salesforce

ServiceNow:

CWE-1177Use of Prohibited Code





What's here


Related content

About CWE




Last modified on Mar 26, 2021