Fallos del tipo CWE-285

1588 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2020-10736HIGHAn authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properEPSS 0.6%CVE-2018-12467MEDIUMdelete package via link exploit in open buildserviceEPSS 0.6%CVE-2021-42331MEDIUMShinHer Information Co., LTD. ShinHer StudyOnline System - Improper Authorization-2EPSS 0.6%CVE-2022-4868MEDIUMImproper Authorization in froxlor/froxlorEPSS 0.6%CVE-2023-0456HIGHApicast proxies the api call with incorrect jwt token to the api backend without proper authorization checkEPSS 0.6%CVE-2023-42491HIGHEisBaer Scada - CWE-285: Improper AuthorizationEPSS 0.6%CVE-2025-63218CRITICALThe Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing auEPSS 0.6%CVE-2023-0609MEDIUMImproper Authorization in wallabag/wallabagEPSS 0.6%CVE-2023-47166HIGHA firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted networEPSS 0.6%CVE-2021-43939HIGHElcomplus SmartPtt Improper AuthorizationEPSS 0.6%CVE-2023-48252HIGHThe vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.EPSS 0.6%CVE-2023-0822HIGHImproper AuthorizationEPSS 0.6%CVE-2023-36826HIGHSentry vulnerable to improper authorization on debug and artifact file downloadsEPSS 0.6%CVE-2024-36108CRITICALMultiple Broken Function-Level Authorization vulnerabilities in casgateEPSS 0.6%CVE-2025-3199MEDIUMageerle ruoyi-ai API Interface SysModelController.java improper authorizationEPSS 0.6%CVE-2019-14828—A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with thEPSS 0.6%CVE-2020-5231MEDIUMOpencast users with ROLE_COURSE_ADMIN can create new usersEPSS 0.6%CVE-2023-20182MEDIUMCisco DNA Center Software API VulnerabilitiesEPSS 0.6%CVE-2022-29490HIGHA vulnerability exists in the Workplace X WebUI in which an authenticated user is able to execute any MicroSCADA internal scripts irrespective of the authenticated user's role.EPSS 0.6%CVE-2025-8261MEDIUMVaelsys VaelsysV4 User Creation vgrid_server.php improper authorizationEPSS 0.6%