CWE-1073—Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses
PUBLISHEDweakness record
released 2019-01-03 · last modified 2025-12-11
Metadata
名称
Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses
描述
The product contains a client with a function or method that contains a large number of data accesses/queries that are sent through a data manager, i.e., does not use efficient database capabilities.
While the interpretation of "large number of data accesses/queries" may vary for each product or developer, CISQ recommends a default maximum of 2 data accesses per function/method.