Skip to main content

Overview

This reference provides detailed information about each impact category, including which CWEs (Common Weakness Enumeration) map to each impact. Use this to understand what types of vulnerabilities fall under each impact category. For a high-level overview of impacts, see Impacts.

Impact details

Execute arbitrary code or commands.Associated CWEs:
Authenticate as another user or hijack sessions.Associated CWEs:
Bypass authorization or escalate privileges.Associated CWEs:
Extract credentials or keys for reuse.Associated CWEs:
Read or manipulate structured data.Associated CWEs:
Read or modify files or paths.Associated CWEs:
Observe or alter data in transit.Associated CWEs:
Sensitive data at rest is not adequately protected.Associated CWEs:
Predict or undermine cryptographic controls.Associated CWEs:
Target end users.Associated CWEs:
Learn internal state or configuration.Associated CWEs:
Avoid logging or monitoring.Associated CWEs:
Exhaust resources or reduce availability.Associated CWEs: