CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A financial application allows users to enter a numeric value for a wire transfer amount. A tester enters a value larger than 2,147,483,647 into the field, and the resulting transfer processes for a negative amount instead. Which vulnerability MOST likely caused this behavior?

  1. AInteger overflow
  2. BLDAP injection
  3. CSession fixation
  4. DCross-site scripting
Show answer & explanation

Correct answer: A. Integer overflow

2,147,483,647 is the maximum value for a signed 32-bit integer; exceeding it causes the value to wrap around to a negative number, a classic integer overflow condition that can corrupt application logic like financial calculations.

Why the other options are wrong

  • B. LDAP injection manipulates directory service queries, not numeric boundaries.
  • C. Session fixation involves forcing a known session ID on a victim, unrelated to numeric input.
  • D. XSS involves script injection into web pages, unrelated to numeric wraparound.

Integer Overflow

A vulnerability that occurs when an arithmetic operation produces a value outside the range representable by the allocated integer type, causing it to wrap around unexpectedly.

  • Signed 32-bit max is 2,147,483,647
  • Wraparound can flip a large positive number to negative
  • Mitigated by input validation and using appropriately sized/unsigned data types

Memory trick: Push past the max and the number flips to the negative side.

More Threats, Vulnerabilities, and Mitigations questions