Common Weakness Enumeration

    CWE Definition / CWE-5

    CWE-5: J2EE Misconfiguration: Data Transmission Without Encryption

    Information sent over a network can be compromised while in transit. An attacker may be able to read or modify the contents if the data are sent in plaintext or are weakly encrypted.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-319: Cleartext Transmission of Sensitive Information