088 – Privacy violation
Description
The system violates one or more privacy requirements.
Impact
Incur in legal trouble due to a violation of user privacy.
Recommendation
Abide by the privacy regulations in force.
Threat
Unauthenticated attacker from the Internet in the application.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): N
- Integrity (VI): N
- Availability (VA): L
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X
Requirements
- 189 - Specify the purpose of data collection
- 310 - Request user consent
- 311 - Demonstrate user consent
- 312 - Allow user consent revocation
- 313 - Inform inability to identify users
- 314 - Provide processing confirmation
- 315 - Provide processed data information
- 316 - Allow rectification requests
- 317 - Allow erasure requests
- 318 - Notify third parties of changes
- 343 - Respect the Do Not Track header