Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-67603MEDIUMLack of client authorization allows arbitrary users to influence the firewall configurationEPSS 0.2%CVE-2026-20661MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOEPSS 0.2%CVE-2025-9988MEDIUMBroadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser CreationEPSS 0.2%CVE-2026-43756MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AnEPSS 0.2%CVE-2025-40830HIGHA vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorEPSS 0.2%CVE-2025-65107MEDIUMLangfuse SSO Account Takeover via CSRF or phishing attackEPSS 0.2%CVE-2022-41610MEDIUMImproper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authEPSS 0.2%CVE-2023-21429MEDIUMImproper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.EPSS 0.2%CVE-2022-43465MEDIUMImproper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service viaEPSS 0.2%CVE-2022-45128MEDIUMImproper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of sEPSS 0.2%CVE-2023-21432MEDIUMImproper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the ownEPSS 0.2%CVE-2026-43775MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app mEPSS 0.2%CVE-2026-64711MEDIUMThis issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS SoEPSS 0.2%CVE-2023-21424MEDIUMImproper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacEPSS 0.2%CVE-2026-17483MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]EPSS 0.1%CVE-2023-21436LOWImproper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.EPSS 0.1%CVE-2023-21423MEDIUMImproper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without pEPSS 0.1%CVE-2023-21452LOWImproper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.EPSS 0.1%CVE-2023-21422MEDIUMImproper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNSEPSS 0.1%CVE-2024-42036LOWAccess permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.1%