Weaknesses of type CWE-264

299 results

Controle de acesso e privilégios inadequado

A fraqueza ocorre quando a aplicação não valida corretamente quem pode fazer o quê, permitindo que usuários acessem recursos ou executem operações acima de seus privilégios. Isso acontece porque as verificações de autorização são ausentes, incompletas ou contornáveis, expondo dados sensíveis ou permitindo ações não autorizadas.

Example

Um usuário comum consegue listar ou modificar dados de outros usuários alterando um ID na URL (ex: /profile/123 → /profile/999) sem que o servidor valide se ele tem permissão para acessar aquele perfil. Ou um atacante executa ações administrativas porque a aplicação só verifica autenticação, não autorização.

How to mitigate

Implemente verificações de autorização em toda operação sensível: valide não apenas se o usuário está logado, mas se ele tem permissão específica para aquele recurso. Use listas de controle de acesso (ACL), roles bem definidas e princípio do menor privilégio. Teste sistematicamente tentativas de escalação e acesso lateral entre usuários.

CVE-2020-3426HIGHCisco IOS Software for Cisco Industrial Routers Virtual-LPWA Unauthorized Access VulnerabilityEPSS 2.2%CVE-2023-2255Remote documents loaded without prompt via IFrameEPSS 2.2%CVE-2017-12214A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified CusEPSS 2.2%CVE-2021-36879CRITICALWordPress uListing plugin <= 2.0.5 - Unauthenticated Privilege Escalation vulnerabilityEPSS 2.2%CVE-2017-12251A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interactEPSS 2.2%CVE-2019-12634HIGHCisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Denial of Service VulnerabilityEPSS 2.0%CVE-2018-0398Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct aEPSS 2.0%CVE-2021-27644DolphinScheduler mysql jdbc connector parameters deserialize remote code executionEPSS 1.9%CVE-2018-0130A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an uEPSS 1.9%CVE-2019-1626HIGHCisco SD-WAN Solution Privilege Escalation VulnerabilityEPSS 1.9%CVE-2018-0399Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve EPSS 1.9%CVE-2018-7500A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escaEPSS 1.8%CVE-2021-22661Changing the password on the module webpage does not require the user to type in the current password first. Thus, the password could be chaEPSS 1.8%CVE-2020-3443HIGHCisco Smart Software Manager On-Prem Privilege Escalation VulnerabilityEPSS 1.8%CVE-2020-13922Apache DolphinScheduler (incubating) Permission vulnerabilityEPSS 1.7%CVE-2017-3813A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthEPSS 1.7%CVE-2017-6620A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unautheEPSS 1.6%CVE-2017-12363A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on EPSS 1.6%CVE-2018-0284Cisco Meraki Local Status Page Privilege Escalation VulnerabilityEPSS 1.6%CVE-2018-0437Cisco Umbrella Enterprise Roaming Client and Enterprise Roaming Module Privilege Escalation VulnerabilityEPSS 1.5%