CWE-282

Improper Ownership Management
AI Translation Available

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Status
draft
Abstraction
class

Common Consequences

access control
Impacts
gain privileges or assume identity

Detection Methods

automated static analysis

Potential Mitigations

Phases:
architecture and design operation
Descriptions:
• Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.