Fallos del tipo CWE-732

790 resultados

Permissões inadequadas em recurso crítico de segurança

A aplicação ou sistema define permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos (chaves API, senhas, tokens), permite alteração de configurações críticas ou compromete a integridade do sistema.

Ejemplo

Um arquivo de configuração contendo credenciais de banco de dados é criado com permissões 644 (leitura global) em vez de 600, permitindo que qualquer usuário do sistema leia as credenciais. Ou um diretório com chaves privadas SSH é criado com permissões 777, deixando-o acessível e modificável por todos.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask 0077 para arquivos sensíveis, chmod 600 para segredos). Revise e audite permissões de recursos críticos regularmente, especialmente após deploy. Use controle de acesso baseado em papéis (RBAC) e aplique o princípio do menor privilégio.

CVE-2026-4757HIGHA VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flEPSS 0.4%CVE-2022-43915MEDIUMIBM App Connect Enterprise Certified ContainerEPSS 0.4%CVE-2025-41712MEDIUMIncorrect Permission Assignment on power analyzerEPSS 0.4%CVE-2023-30606MEDIUMMultisite denial of service through unsanitized dynamic dispatch to SiteSetting in DiscourseEPSS 0.4%CVE-2025-3936MEDIUMIncorrect Permission Assignment for Critical ResourceEPSS 0.4%CVE-2024-11497HIGHPhoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalationEPSS 0.4%CVE-2023-4777LOWIncorrect Permission Assignment on Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier EPSS 0.4%CVE-2025-6297HIGHdpkg-deb: Fix cleanup for control member with restricted directoriesEPSS 0.4%CVE-2020-10140HIGHAcronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed fEPSS 0.4%CVE-2026-76104MEDIUMDell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A hiEPSS 0.4%CVE-2020-16202WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code exeEPSS 0.4%CVE-2023-1692HIGHThe window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.4%CVE-2017-12167MEDIUMIt was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user tEPSS 0.4%CVE-2025-0064HIGHImproper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)EPSS 0.4%CVE-2023-35870MEDIUMImproper Access Control in SAP S/4HANA (Manage Journal Entry Template)EPSS 0.4%CVE-2016-2121MEDIUMA permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitiveEPSS 0.4%CVE-2020-36770HIGHpkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root fEPSS 0.4%CVE-2025-43808MEDIUMThe Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10,EPSS 0.4%CVE-2026-58424HIGHPermanent Fork PR Workflow Approval Gate BypassEPSS 0.4%CVE-2023-0834HIGHIncorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issueEPSS 0.4%