Fallos del tipo CWE-285

1605 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-43289MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A maliciEPSS 0.1%CVE-2026-2974LOWAliasVault App Backup aliasvault.xml backupEPSS 0.1%CVE-2026-47053MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2025-68712MEDIUMSpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentiEPSS 0.1%CVE-2026-60842MEDIUMVulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affectEPSS 0.1%CVE-2023-44123MEDIUMBluetooth - Theft and (over-)write of arbitrary files with system privilege via PendingIntent hijackingEPSS 0.1%CVE-2023-24476LOWPTC Vuforia Studio Improper AuthorizationEPSS 0.1%CVE-2025-8532MEDIUMIDOR in Bimser's eBA Document and Workflow Management SystemEPSS 0.1%CVE-2023-44125MEDIUMPersonalized service - Theft and (over-)write of arbitrary files with system privilege via PendingIntent hijackingEPSS 0.1%CVE-2026-21097MEDIUMImproper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary EPSS 0.1%CVE-2023-28556HIGHImproper Authorization in HLOSEPSS 0.1%CVE-2026-0072CRITICALIn addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead EPSS 0.1%CVE-2026-60957MEDIUMVulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.1%CVE-2026-60911MEDIUMVulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.1%CVE-2026-20656LOWA logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. AnEPSS 0.1%CVE-2026-62563MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2022-39905MEDIUMImplicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive informatiEPSS 0.1%CVE-2021-25459MEDIUMAn improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockEPSS 0.1%CVE-2026-20666MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sEPSS 0.1%CVE-2024-51525MEDIUMPermission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%