CWE · MITRE source
CWE-223Omission of Security-relevant Information
The product does not record or display information that would be important for identifying the source or nature of an attack, or determining if an action is safe.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: full · 4 mapping(s) from 2 framework(s): STIG ubuntu 22 04 2 (full) · STIG ubuntu 24 04 2 (mostly)
OWASP Top 10 for Web (2025)
This weakness contributes to A09:2025 Security Logging and Alerting Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2023-31191 UPD | 6.5 | 9.3 | 0.0035 | 2023-07-11 |
CVE-2026-31890 UPD | 4.1 | 5.5 | 0.0014 | 2026-03-12 |
CVE-2023-28360 UPD | 3.9 | 4.3 | 0.0084 | 2023-05-11 |
CVE-2023-29156 UPD | 3.7 | 4.7 | 0.0032 | 2023-07-11 |
CVE-2024-52813 UPD | 3.7 | 4.3 | 0.0048 | 2025-01-07 |
CVE-2022-22563 UPD | 3.5 | 4.4 | 0.0022 | 2022-04-08 |
CVE-2022-44646 UPD | 2.2 | 2.2 | 0.0036 | 2022-11-03 |
CVE-2025-52926 UPD | 2.2 | 2.7 | 0.0014 | 2025-06-23 |