The product uses or accesses a resource that has not been initialized.
Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all required steps.
Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.
Avoid race conditions (CWE-362) during initialization routines.
Run or compile the product with settings that generate warnings about uninitialized variables or data.
Our security experts can help you identify and remediate CWE-908 vulnerabilities in your codebase.
Get Security Assessment