Fallos del tipo CWE-285

1605 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2022-22268MEDIUMIncorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox GuEPSS 0.1%CVE-2024-42032MEDIUMAccess permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.1%CVE-2024-43051MEDIUMImproper Authorization in SPS-HLOSEPSS 0.1%CVE-2026-12065LOWGroww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url schemeEPSS 0.1%CVE-2022-36852LOWImproper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application daEPSS 0.1%CVE-2026-12190MEDIUMGenspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url schemeEPSS 0.1%CVE-2026-12189MEDIUMMoovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url schemeEPSS 0.1%CVE-2024-38425MEDIUMImproper Authorization in PerformanceEPSS 0.1%CVE-2021-25382MEDIUMAn improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contentsEPSS 0.1%CVE-2022-22269MEDIUMKeeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a localEPSS 0.1%CVE-2026-78236HIGHInsecure PIN derivation mechanism in Admin By Request (ABR)EPSS 0.1%CVE-2022-22267MEDIUMImplicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running applicationEPSS 0.1%CVE-2022-22272MEDIUMImproper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE EPSS 0.1%CVE-2022-30757MEDIUMImproper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permissioEPSS 0.1%CVE-2026-0017HIGHIn onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could leadEPSS 0.1%CVE-2021-25460MEDIUMAn improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BEPSS 0.1%CVE-2025-30508MEDIUMImproper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of serviEPSS 0.1%CVE-2022-33722MEDIUMImplicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC addressEPSS 0.1%CVE-2022-33702MEDIUMImproper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass KnoxgEPSS 0.1%CVE-2026-16925HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%