CWE-201β€”Insertion of Sensitive Information Into Sent Data

PUBLISHEDweakness record
released 2006-07-19 Β· last modified 2026-04-30
CWE-201 - Insertion of Sensitive Information Into Sent Data - Diagram

Metadata

CWE ID:
CWE-201
Abstraction:
Base
Structure:
Simple
Status:
Draft
Release Date:
2006-07-19
Latest Modification Date:
2026-04-30

Weakness Name

Insertion of Sensitive Information Into Sent Data

Description

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Common Consequences

Scope:
Confidentiality
Impact:
Read Files or Directories, Read Memory, Read Application Data
Notes:
Sensitive data may be exposed to attackers.

Related Weaknesses

Related Alerts