Skip to main content
. 2022 Mar 11;10(3):e30691. doi: 10.2196/30691

Table 3.

Comparison of Common Weakness Enumerators (CWEs) in the Corona-Warn [89] and MyTrace [97] apps.

CWE Corona-Warn MyTrace
89: A (SQLa) Command Local SQL injection possible but data encrypted Local SQL injection possible and data not encrypted
276: Incorrect Default Permissions N/Ab Permissions for tasks, Bluetooth administration, and external storage
295: Improper Certificate Validation Vulnerable to SSLc MITMd attack N/A
532: Insertion of Sensitive Information into Log File Sensitive information is encrypted Excessive information logged
327: Use of a Broken or Risky Cryptographic Algorithm Weak hash function in SSL N/A

aSQL: Structured Query Language.

bN/A: not applicable.

cSSL: Secure Socket Layer.

dMITM: man in the middle.