CWE Database
/

CWE-446

Back to CWE list

CWE-446

UI Discrepancy for Security Feature

Class
Incomplete

Description

The user interface does not correctly enable or configure a security feature, but the interface provides feedback that causes the user to believe that the feature is in a secure state.

When the user interface does not properly reflect what the user asks of it, then it can lead the user into a false sense of security. For example, the user might check a box to enable a security option to enable encrypted communications, but the product does not actually enable the encryption. Alternately, the user might provide a "restrict ALL" access control rule, but the product only implements "restrict SOME".

Common Consequences

Scope

Other

Impact

Varies by Context

CVE-1999-1446

UI inconsistency; visited URLs list not cleared when "Clear History" option is selected.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now