CWE-1073 — Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses
CWE-1073: Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Base |
| Status | Incomplete |
| Likelihood of exploit | — |
Description
The product contains a client with a function or method that contains a large number of data accesses/queries that are sent through a data manager, i.e., does not use efficient database capabilities.
While the interpretation of "large number of data accesses/queries" may vary for each product or developer, CISQ recommends a default maximum of 2 data accesses per function/method.
Common consequences
- Other: Reduce Performance
Mitigations
(none listed)
References
- CWE page: https://cwe.mitre.org/data/definitions/1073.html
- CWE list: https://cwe.mitre.org/data/index.html