Fallos del tipo CWE-602

174 resultados

Confiança em mecanismo de segurança implementado no cliente

O servidor delega a responsabilidade de uma proteção de segurança para o cliente executar, assumindo que ele vai cumprir. Isso é perigoso porque um atacante controla o cliente e pode simplesmente ignorar, contornar ou desabilitar essa proteção, deixando o servidor vulnerável.

Ejemplo

Um servidor web que valida permissões de acesso apenas via JavaScript no navegador, sem verificar novamente no backend. Um atacante desabilita o JavaScript ou intercepta a requisição, acessando dados que não deveria.

Cómo mitigar

Implemente toda validação crítica de segurança no servidor, nunca confie em verificações feitas apenas no cliente. O cliente pode fazer validação por UX, mas o servidor deve sempre validar independentemente autenticação, autorização, entrada de dados e regras de negócio.

CVE-2025-27367MEDIUMIBM OpenPages with Watson improper input validationEPSS 0.2%CVE-2026-17953MEDIUMInsufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigationEPSS 0.2%CVE-2026-14047MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a EPSS 0.2%CVE-2026-14081MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2025-36102LOWIBM Controller Validation BypassEPSS 0.2%CVE-2026-17985MEDIUMInsufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a cEPSS 0.2%CVE-2026-11014MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a EPSS 0.2%CVE-2026-13894MEDIUMInsufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bEPSS 0.2%CVE-2025-14687MEDIUMClient-Side Enforcement of Server-Side Security in IBM Db2 Intelligence CenterEPSS 0.2%CVE-2026-17821MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a EPSS 0.2%CVE-2023-3747MEDIUMInsufficient Validation on Override Codes for Always-Enabled WARP ModeEPSS 0.2%CVE-2026-17960MEDIUMInsufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass no-refeEPSS 0.2%CVE-2026-77793MEDIUMRegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price FieldEPSS 0.2%CVE-2026-29077HIGHFrappe: Broken Access Control in DocShareEPSS 0.2%CVE-2025-36410LOWMultiple vulnerabilities found in IBM ApplinX.EPSS 0.2%CVE-2025-2138LOWIBM Engineering Requirements Management Doors Next data modificationEPSS 0.2%CVE-2025-2139LOWIBM Engineering Requirements Management Doors Next security bypassEPSS 0.2%CVE-2026-11236HIGHInsufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rEPSS 0.2%CVE-2026-11092HIGHInsufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2026-42329MEDIUMIris has an Open Redirect issueEPSS 0.2%