The mapper suggests likely OWASP categories from finding language for reviewer confirmation.
No clear OWASP category has been detected yet.
Incorrect mapping can weaken reporting clarity, compliance traceability and remediation ownership.
Review the finding behavior, affected control, exploit path and asset type, then choose the OWASP and CWE mapping that best describes root cause.
Have the technical reviewer confirm the final OWASP/CWE mapping before publishing the report.
Matching OWASP categories will appear here.