Back to Labs
Weakness (CWE)

CWE-1284

Improper Validation of Specified Quantity in Input

About

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Specified quantities include size, length, frequency, price, rate, number of operations, time, and others. Code may rely on specified quantities to allocate resources, perform calculations, control iteration, etc.

Common consequences

  • Other, Integrity, Availability → Varies by Context, DoS: Resource Consumption (CPU), Modify Memory, Read Memory

Mitigations

  • Implementation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input

CVEs with this weakness

Frequently asked questions

What is CWE-1284?

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. Specified quantities include size, length, frequency, price, rate, number of operations, time, and others. Code may rely on specified quantities to allocate resources, perform calculations, control iteration, etc.

How many CVEs does Rainforest track for CWE-1284?

Rainforest Labs currently tracks 1 published CVEs mapped to CWE-1284. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.