CWE Database
/

CWE-221

Back to CWE list

CWE-221

Information Loss or Omission

Class
Incomplete

Description

The product does not record, or improperly records, security-relevant information that leads to an incorrect decision or hampers later analysis.

Common Consequences

Scope

Non-Repudiation

Impact

Hide Activities

CVE-2004-2227

Web browser's filename selection dialog only shows the beginning portion of long filenames, which can trick users into launching executables with dangerous extensions.

CVE-2003-0412

application server does not log complete URI of a long request (truncation).

CVE-1999-1029

Login attempts are not recorded if the user disconnects before the maximum number of tries.

CVE-2002-0725

Attacker performs malicious actions on a hard link to a file, obscuring the real target file.

CVE-1999-1055

Product does not warn user when document contains certain dangerous functions or macros.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now