Fallos del tipo CWE-285

1604 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-49701HIGHMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 1.1%CVE-2021-32619CRITICALStatic imports inside dynamically imported modules do not adhere to permission checksEPSS 1.1%CVE-2019-1851MEDIUMCisco Identity Services Engine Arbitrary Client Certificate Creation VulnerabilityEPSS 1.1%CVE-2024-43482MEDIUMMicrosoft Outlook for iOS Information Disclosure VulnerabilityEPSS 1.1%CVE-2019-14883LOWA vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notificatioEPSS 1.1%CVE-2021-1576HIGHCisco Business Process Automation Privilege Escalation VulnerabilitiesEPSS 1.1%CVE-2021-35964HIGHLearningdigital.com, Inc. Orca HCM - Broken AuthenticationEPSS 1.1%CVE-2024-26291HIGHAuthenticated Arbitrary File Read affecting Avid NEXISEPSS 1.1%CVE-2026-25893CRITICALFUXA Unauthenticated Remote Code Execution via Admin JWT MintingEPSS 1.1%CVE-2022-38375HIGHAn improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticatEPSS 1.1%CVE-2020-36696HIGHProduct Input Fields for WooCommerce <= 1.2.6 - Missing AuthorizationEPSS 1.1%CVE-2023-30467HIGHImproper Authorization Vulnerability in Milesight Network Video Recorder (NVR)EPSS 1.1%CVE-2024-43729MEDIUMAdobe Experience Manager | Improper Authorization (CWE-285)EPSS 1.1%CVE-2017-1002151—Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorizationEPSS 1.1%CVE-2020-15087HIGHPrivilege escalation in PrestoEPSS 1.1%CVE-2019-6582—A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), SivEPSS 1.1%CVE-2020-15084HIGHAuthorization bypass in express-jwtEPSS 1.1%CVE-2020-10517—Improper access control in GitHub Enterprise Server leading to the enumeration of private repository namesEPSS 1.1%CVE-2018-14666MEDIUMAn improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host rEPSS 1.0%CVE-2025-30392CRITICALAzure AI Bot Elevation of Privilege VulnerabilityEPSS 1.0%