Fallos del tipo CWE-15

81 resultados

Controle externo de configurações do sistema

Ocorre quando a aplicação permite que um atacante modifique configurações críticas do sistema ou da aplicação através de entrada externa (parâmetros, arquivos, variáveis de ambiente). Isso pode comprometer a integridade, disponibilidade ou segurança da aplicação, já que configurações maliciosas podem desabilitar proteções, redirecionar recursos ou alterar comportamentos sensíveis.

Ejemplo

Uma aplicação web que lê a URL do banco de dados de um parâmetro GET sem validação (ex: ?db_host=atacante.com), ou um serviço que respeita variáveis de ambiente não validadas para definir modo debug, diretório de upload ou chaves de segurança. Um atacante pode redirecionar para seu próprio servidor ou ativar funcionalidades perigosas.

Cómo mitigar

Nunca permita que configurações críticas sejam alteradas por entrada do usuário; se necessário, use whitelist rígida de valores pré-aprovados. Armazene configurações sensíveis em arquivos protegidos (não acessíveis via web), valide e sanitize toda entrada externa, e aplique princípio do menor privilégio nas permissões de arquivo e processo.

CVE-2026-16708HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.2%CVE-2023-32076MEDIUMin-toto vulnerable to Configuration Read From Local DirectoryEPSS 0.2%CVE-2021-31338A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuratioEPSS 0.2%CVE-2025-27253MEDIUMA CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attEPSS 0.2%CVE-2026-22750HIGHSSL bundle configuration silently bypassed in Spring Cloud GatewayEPSS 0.2%CVE-2026-43531HIGHOpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env FileEPSS 0.2%CVE-2023-6154HIGHLocal privilege escalation in Bitdefender Total Security (VA-11168)EPSS 0.2%CVE-2026-1784HIGHOse-cluster-ingress-operator: remote code execution through haproxy configuration injectionEPSS 0.2%CVE-2026-33092HIGHLocal privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (mEPSS 0.2%CVE-2026-0495MEDIUMMultiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)EPSS 0.2%CVE-2025-0425HIGHLocal Privilege Escalation via Config ManipulationEPSS 0.2%CVE-2025-64726HIGHExternal Control of System or Configuration Setting and Uncontrolled Search Path Element in sfwEPSS 0.1%CVE-2026-0232MEDIUMCortex XDR Agent: Local Administrator can disable the agent on WindowsEPSS 0.1%CVE-2026-41384HIGHOpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI BackendEPSS 0.1%CVE-2026-85217HIGHMan-in-the-Middle (MITM) Vulnerability in Autodesk Fusion DesktopEPSS 0.1%CVE-2026-41489HIGHPi-hole: Local privilege escalation via config-controlled path in root-executed service hooksEPSS 0.1%CVE-2026-19884HIGHIn Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trustEPSS 0.1%CVE-2026-41294HIGHOpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env FileEPSS 0.1%CVE-2026-21422LOWDell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setting vulnerability. A EPSS 0.1%CVE-2026-19592HIGHOpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata withoEPSS 0.1%