ClassIncomplete
CWE-706Use of Incorrectly-Resolved Name or Reference
Category: other
Description
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
Common consequences· 1
- Confidentiality / Integrity — Read Application Data, Modify Application Data
Related CAPEC attack patterns· 4
References
Exploits (incoming)4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Passing Local Filenames to Functions That Expect a URLcapec-48 | 100% | live |
| AttackPattern | Create files with the same name as files protected with a higher classificationcapec-177 | 100% | live |
| AttackPattern | DLL Side-Loadingcapec-641 | 100% | live |
| AttackPattern | Redirect Access to Librariescapec-159 | 100% | live |
(incoming)11
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | Apache Tomcat Path Equivalence Vulnerabilitycve-2025-24813 | 0% | live |
| Vulnerability | CVE-2025-30849cve-2025-30849 | 0% | live |
| Vulnerability | CVE-2025-30870cve-2025-30870 | 0% | live |
| Vulnerability | CVE-2025-3941cve-2025-3941 | 0% | live |
| Vulnerability | CVE-2025-48136cve-2025-48136 | 0% | live |
| Vulnerability | CVE-2025-65474cve-2025-65474 | 0% | live |
| Vulnerability | CVE-2026-25890cve-2026-25890 | 0% | live |
| Vulnerability | CVE-2026-35039cve-2026-35039 | 0% | live |
| Vulnerability | CVE-2026-35666cve-2026-35666 | 0% | live |
| Vulnerability | CVE-2026-40912cve-2026-40912 | 0% | live |
| KEVEntry | Ivanti MobileIron Multiple Products Remote Code Execution Vulnerabilitykev-cve-2020-15505 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.