CWE-1447: Category: General Software Weaknesses that Appear in Products that Use or Support AI/ML Technology

ClassIncomplete

This category lists general software weaknesses in software that insecurely uses AI/ML components, but frequently appear in many kinds of software products that do not use AI/ML.

View on MITRE
Back to CWE Lookup

Extended Description

This entry is a Category. Using categories for mapping has been discouraged since 2019. Categories are informal organizational groupings of weaknesses that can help CWE users with data aggregation, navigation, and browsing. However, they are not weaknesses in themselves. CWE users might be tempted to use this CWE for mapping, but it is a category (see Reasons). Mappers should consider whether a weakness is unique to AI/ML (in which case a high-level Pillar or class might still apply), or if it is a general software weakness that happens to appear in AI/ML related software.

Technical Details

Structure
Simple
Vulnerability Mapping
PROHIBITED

Applicable To

Languages
Platforms

Source-backed guidance

Additional facts reviewed against primary or authoritative security sources.

Use CWE-1447 to navigate General Software Weaknesses that Appear in Products that Use or Support AI/ML Technology

MITRE defines CWE-1447 as an organizational category with 16 members, including CWE-22, CWE-77, CWE-78, CWE-79, and CWE-94. Use it for aggregation, navigation, and browsing; because a category is not itself a weakness, do not use it as the root-cause mapping for a vulnerability. Follow the member CWE entries for implementation and verification guidance.

CWE-1447: General Software Weaknesses that Appear in Products that Use or Support AI/ML TechnologyMITRE CWE

Frequently Asked Questions

What is CWE-1447: Category: General Software Weaknesses that Appear in Products that Use or Support AI/ML Technology?+

CWE-1447: Category: General Software Weaknesses that Appear in Products that Use or Support AI/ML Technology is a Common Weakness Enumeration (CWE) entry maintained by MITRE. This category lists general software weaknesses in software that insecurely uses AI/ML components, but frequently appear in many kinds of software products that do not use AI/ML. This entry is a Category. Using categories for mapping has been discouraged since 2019. Categories are informal organizational groupings of weaknesses that can help CWE users with data aggregation, navigation, and browsing. However, they are not weaknesses in themselves. CWE users might be tempted to use this CWE for mapping, but it is a category (see Reasons). Mappers should consider whether a weakness is unique to AI/ML (in which case a high-level Pillar or class might still apply), or if it is a general software weakness that happens to appear in AI/ML related software.

What is the difference between a CWE and a CVE?+

A CWE (Common Weakness Enumeration) like CWE-1447 describes a category of software weakness — the underlying flaw type. A CVE (Common Vulnerabilities and Exposures) identifies a specific, real-world vulnerability in a particular product. In short, a CWE is the kind of mistake, and a CVE is an instance of that mistake being found in software.

Learn More

Advertisement