Fallos del tipo CWE-306

2632 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2020-27225—In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web seEPSS 0.3%CVE-2025-36757MEDIUMBypass of administrator login screen in SolaX CloudEPSS 0.3%CVE-2025-11728MEDIUMOceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status UpdateEPSS 0.3%CVE-2026-19853MEDIUMCyberTutor|NewSiteServer (NSS) - Missing AuthenticationEPSS 0.3%CVE-2026-44413HIGHIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised accessEPSS 0.3%CVE-2023-37325MEDIUMD-Link DAP-2622 DDP Set SSID List Missing Authentication VulnerabilityEPSS 0.3%CVE-2026-83343HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.3%CVE-2026-60931HIGHVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.3%CVE-2026-70973HIGHVulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). TheEPSS 0.3%CVE-2026-60496HIGHVulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement product of Oracle JD Edwards (component: Advanced Pricing). TEPSS 0.3%CVE-2026-60988HIGHVulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versiEPSS 0.3%CVE-2026-46958HIGHVulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions thEPSS 0.3%CVE-2026-60497HIGHVulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported versiEPSS 0.3%CVE-2026-60927HIGHVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.3%CVE-2026-60498HIGHVulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The suEPSS 0.3%CVE-2026-60619HIGHVulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The sEPSS 0.3%CVE-2026-60604HIGHVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.3%CVE-2026-61141HIGHVulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that EPSS 0.3%CVE-2026-60769HIGHVulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-61188HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The sEPSS 0.3%