Umbra Wiki weakness weakness/CWE-1083
Back to wiki

CWE-1083 — Data Access from Outside Expected Data Manager Component

provenance: imported · CWE: CWE-1083

CWE-1083: Data Access from Outside Expected Data Manager Component

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Incomplete
Likelihood of exploit

Description

The product is intended to manage data access through a particular data manager component such as a relational or non-SQL database, but it contains code that performs data access operations without using that component.

When the product has a data access component, the design may be intended to handle all data access operations through that component. If a data access operation is performed outside of that component, then this may indicate a violation of the intended design.

Common consequences

  • Other: Reduce Reliability

Mitigations

(none listed)

References

  • CWE page: https://cwe.mitre.org/data/definitions/1083.html
  • CWE list: https://cwe.mitre.org/data/index.html