Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2024-13552MEDIUMSupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object ReferenceEPSS 0.3%CVE-2019-1603HIGHCisco NX-OS Software Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-34315MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affeEPSS 0.3%CVE-2023-52539HIGHPermission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confiEPSS 0.3%CVE-2025-54822MEDIUMAn improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOEPSS 0.3%CVE-2024-45307HIGHSudoBot missing authorization check in `-config` commandEPSS 0.3%CVE-2026-13591LOWDeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorizationEPSS 0.3%CVE-2026-6938MEDIUMIBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special queryEPSS 0.3%CVE-2021-3991MEDIUMImproper Authorization in dolibarr/dolibarrEPSS 0.3%CVE-2026-11934HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2025-27601MEDIUMUmbraco Allows Improper API Access Control to Low-Privilege Users to Data Type FunctionalityEPSS 0.3%CVE-2018-1113MEDIUMsetup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This vioEPSS 0.3%CVE-2026-92799MEDIUMOnline Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_dataEPSS 0.3%CVE-2025-15122LOWJeecgBoot datarule loadDatarule improper authorizationEPSS 0.3%CVE-2025-15123LOWJeecgBoot datarule improper authorizationEPSS 0.3%CVE-2023-25074HIGHCompetency access levels not enforced in the serverEPSS 0.3%CVE-2023-23568MEDIUM Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields.EPSS 0.3%CVE-2026-2015MEDIUMPortabilis i-Educar Final Status Import FinalStatusImportService.php improper authorizationEPSS 0.3%CVE-2026-18207MEDIUMKeycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matchingEPSS 0.3%CVE-2025-15125LOWJeecgBoot queryDepartPermission improper authorizationEPSS 0.3%