CWE-486

Overview
  • CWE ID
  • 486
  • CWE Name
  • Comparison of Classes by Name
  • CWE Abstraction
  • Variant
  • CWE structure
  • Simple
  • CWE Status
  • Draft
Description
The program compares classes by name, which can cause it to use the wrong class when multiple classes can have the same name.
Extended Description
If the decision to trust the methods and data of an object is based on the name of a class, it is possible for malicious users to send objects of the same name as trusted classes and thereby gain the trust afforded to known classes and types.
Related CWEs
CWE ID View ID Nature Ordinal
1025 1000 ChildOf Primary