Umbra Wiki weakness weakness/CWE-105
Back to wiki

CWE-105 — Struts: Form Field Without Validator

provenance: imported · CWE: CWE-105

CWE-105: Struts: Form Field Without Validator

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit

Description

The product has a form field that is not validated by a corresponding validation form, which can introduce other weaknesses related to insufficient input validation.

Omitting validation for even a single input field may give attackers the leeway they need to compromise the product. Although J2EE applications are not generally susceptible to memory corruption attacks, if a J2EE application interfaces with native code that does not perform array bounds checking, an attacker may be able to use an input validation mistake in the J2EE application to launch a buffer overflow attack.

Common consequences

  • Integrity: Unexpected State
  • Integrity: Bypass Protection Mechanism

Mitigations

Implementation — Validate all form fields. If a field is unused, it is still important to constrain it so that it is empty or undefined.

References

  • CWE page: https://cwe.mitre.org/data/definitions/105.html
  • CWE list: https://cwe.mitre.org/data/index.html