Table 3.
| CWE | Corona-Warn | MyTrace |
| 89: A (SQLa) Command | Local SQL injection possible but data encrypted | Local SQL injection possible and data not encrypted |
| 276: Incorrect Default Permissions | N/Ab | Permissions for tasks, Bluetooth administration, and external storage |
| 295: Improper Certificate Validation | Vulnerable to SSLc MITMd attack | N/A |
| 532: Insertion of Sensitive Information into Log File | Sensitive information is encrypted | Excessive information logged |
| 327: Use of a Broken or Risky Cryptographic Algorithm | Weak hash function in SSL | N/A |
aSQL: Structured Query Language.
bN/A: not applicable.
cSSL: Secure Socket Layer.
dMITM: man in the middle.