Weaknesses of type CWE-840

99 results

Erros de Lógica de Negócio

Fraqueza que ocorre quando a implementação não respeita corretamente as regras de negócio, permitindo estados ou operações que não deveriam ser possíveis. O código pode estar tecnicamente correto (sem buffer overflow, injeção etc), mas executa fluxos que violam as restrições do domínio, levando a fraudes, escalação de privilégios ou corrupção de dados.

Example

Um e-commerce que permite aplicar desconto infinitas vezes no carrinho porque falta validação de regra de negócio; ou um sistema de transferência bancária que permite débito sem verificar saldo mínimo exigido pela política institucional. O código roda sem erros, mas o negócio é prejudicado.

How to mitigate

Modele explicitamente as regras de negócio (ex: pré-condições, limites, sequências permitidas) e implemente validações em cada ponto crítico; revise fluxos com especialistas do domínio durante design e testes, não apenas verificando segurança técnica, mas coerência com políticas operacionais.

CVE-2023-6566MEDIUMBusiness Logic Errors in microweber/microweberEPSS 0.5%CVE-2025-2323MEDIUM274056675 springboot-openai-chatgpt Number of Question questionCou updateQuestionCou behavioral workflowEPSS 0.5%CVE-2023-3228MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2025-2321MEDIUM274056675 springboot-openai-chatgpt addData logic errorEPSS 0.4%CVE-2024-6446LOWBusiness Logic Errors in GitLabEPSS 0.4%CVE-2024-6577MEDIUMUnclaimed S3 Bucket Usage in pytorch/serveEPSS 0.4%CVE-2025-1908HIGHBusiness Logic Errors in GitLabEPSS 0.4%CVE-2024-1682MEDIUMUnclaimed S3 Bucket Reference in psf/requests DocumentationEPSS 0.4%CVE-2024-45424MEDIUMZoom Workplace Apps - Business Logic ErrorEPSS 0.4%CVE-2018-25104MEDIUMCoinGate Plugin Payment callback.php postProcess logic errorEPSS 0.4%CVE-2026-85030MEDIUMHKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic errorEPSS 0.4%CVE-2025-8991MEDIUMlinlinjava litemall Business Logic express logic errorEPSS 0.3%CVE-2026-8738MEDIUMSanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pay logic errorEPSS 0.3%CVE-2026-1322MEDIUMBusiness Logic Errors in GitLabEPSS 0.3%CVE-2023-6514HIGH The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of tEPSS 0.3%CVE-2025-13239MEDIUMBdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution submit_checkout behavioral workflowEPSS 0.3%CVE-2026-1599MEDIUMBdtask Bhojon All-In-One Restaurant Management System Checkout placeorder logic errorEPSS 0.3%CVE-2026-1274MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-6601LOWBusiness Logic Errors in GitLabEPSS 0.3%CVE-2025-4037MEDIUMcode-projects ATM Banking moneyWithdraw logic errorEPSS 0.3%