CWE-1073

Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses
AI Translation Available

The product contains a client with a function or method that contains a large number of data accesses/queries that are sent through a data manager, i.e., does not use efficient database capabilities.

Status
incomplete
Abstraction
base
SQL Database Server

While the interpretation of 'large number of data accesses/queries' may vary for each product or developer, CISQ recommends a default maximum of 2 data accesses per function/method.

Common Consequences

other
Impacts
reduce performance

Potential Mitigations