Fallos del tipo CWE-285

1587 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2020-15084HIGHAuthorization bypass in express-jwtEPSS 1.1%CVE-2018-14666MEDIUMAn improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host rEPSS 1.0%CVE-2025-30392CRITICALAzure AI Bot Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2021-21511HIGHDell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attackEPSS 1.0%CVE-2020-2050HIGHPAN-OS: Authentication bypass vulnerability in GlobalProtect SSL VPN client certificate verificationEPSS 1.0%CVE-2021-41564MEDIUMTad Honor - Improper AuthorizationEPSS 1.0%CVE-2021-41976MEDIUMTad Uploader - Improper AuthorizationEPSS 1.0%CVE-2022-1224MEDIUMImproper Authorization in phpipam/phpipamEPSS 1.0%CVE-2026-27823HIGHRemote Code Execution Vulnerability in EGroupwareEPSS 1.0%CVE-2021-41568MEDIUMTad Web - Improper AuthorizationEPSS 1.0%CVE-2019-3849MEDIUMA vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses oEPSS 1.0%CVE-2023-33142MEDIUMMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2019-12635MEDIUMCisco Content Security Management Appliance Information Disclosure VulnerabilityEPSS 1.0%CVE-2020-6311MEDIUMBanking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not corrEPSS 1.0%CVE-2022-0587HIGHImproper Authorization in librenms/librenmsEPSS 1.0%CVE-2024-2557MEDIUMkishor-23 Food Waste Management System admin.php improper authorizationEPSS 1.0%CVE-2026-48579CRITICALMicrosoft Exchange Online Information Disclosure VulnerabilityEPSS 1.0%CVE-2021-41308—Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File RepliEPSS 1.0%CVE-2022-29233MEDIUMImproper access control for breakout rooms in BigBlue ButtonEPSS 1.0%CVE-2021-22863—Improper access control in GitHub Enterprise Server leading to unauthorized changes to maintainer permissions on pull requestsEPSS 1.0%