Fallos del tipo CWE-610

96 resultados

Controle de acesso inadequado

A aplicação falha em validar corretamente se um usuário tem permissão para acessar um recurso, funcionalidade ou dado específico. Isso permite que atacantes contornem restrições e acessem informações confidenciais, modifiquem dados ou executem ações que não deveriam estar autorizadas a fazer.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado, mas não valida se ele é dono da conta antes de exibir o extrato. Um atacante muda o ID da conta na URL (de ?conta=123 para ?conta=456) e consegue ver extratos alheios.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível: valide que o usuário não apenas está autenticado, mas que possui permissão específica para aquele recurso. Use modelos de controle de acesso bem definidos (RBAC, ABAC) e revise sistematicamente os pontos críticos onde recursos são expostos.

CVE-2023-21097HIGHIn toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escEPSS 0.2%CVE-2022-44747LOWLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2022-20515MEDIUMIn onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to aEPSS 0.2%CVE-2022-46868MEDIUMLocal privilege escalation during recovery due to improper soft link handling. The following products are affected: Acronis Cyber Protect HoEPSS 0.2%CVE-2026-28721HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2026-28722HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2024-13177MEDIUMSymlink Following in Netskope Client Postinstall ScriptEPSS 0.1%CVE-2025-48963HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.1%CVE-2022-20550HIGHIn Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local esEPSS 0.1%CVE-2023-20964HIGHIn multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local EPSS 0.1%CVE-2022-20199MEDIUMIn multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local infoEPSS 0.1%CVE-2024-49722MEDIUMIn showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to EPSS 0.1%CVE-2025-48654HIGHIn onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to lEPSS 0.1%CVE-2024-49728MEDIUMIn generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lEPSS 0.1%CVE-2025-0082MEDIUMIn multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confuseEPSS 0.1%CVE-2026-21810MEDIUMHCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checkingEPSS 0.1%