Fallos del tipo CWE-840

99 resultados

Erros de Lógica de Negócio

É quando o código implementa corretamente a sintaxe, mas a lógica por trás não reflete as regras de negócio esperadas — permitindo operações que deveriam ser bloqueadas ou produzindo resultados incorretos. O atacante explora brechas nessas regras para contornar controles, duplicar recursos, ou chegar a estados inválidos.

Ejemplo

Um e-commerce que valida se o preço é positivo, mas não valida se o desconto pode ser maior que o preço final, permitindo que o cliente pague valor negativo. Ou um sistema que transfere saldo entre contas sem verificar se o saldo é suficiente antes de débito.

Cómo mitigar

Defina explicitamente as regras de negócio (pré e pós-condições), documente-as e implemente testes automatizados que cobram cada cenário — incluindo casos extremos e cenários de ataque. Revise a lógica de autenticação, autorização e transações críticas com produto e segurança.

CVE-2023-6566MEDIUMBusiness Logic Errors in microweber/microweberEPSS 0.5%CVE-2025-2323MEDIUM274056675 springboot-openai-chatgpt Number of Question questionCou updateQuestionCou behavioral workflowEPSS 0.5%CVE-2023-3228MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2025-2321MEDIUM274056675 springboot-openai-chatgpt addData logic errorEPSS 0.4%CVE-2024-6446LOWBusiness Logic Errors in GitLabEPSS 0.4%CVE-2024-6577MEDIUMUnclaimed S3 Bucket Usage in pytorch/serveEPSS 0.4%CVE-2025-1908HIGHBusiness Logic Errors in GitLabEPSS 0.4%CVE-2024-1682MEDIUMUnclaimed S3 Bucket Reference in psf/requests DocumentationEPSS 0.4%CVE-2024-45424MEDIUMZoom Workplace Apps - Business Logic ErrorEPSS 0.4%CVE-2018-25104MEDIUMCoinGate Plugin Payment callback.php postProcess logic errorEPSS 0.4%CVE-2026-85030MEDIUMHKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic errorEPSS 0.4%CVE-2025-8991MEDIUMlinlinjava litemall Business Logic express logic errorEPSS 0.3%CVE-2026-8738MEDIUMSanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pay logic errorEPSS 0.3%CVE-2026-1322MEDIUMBusiness Logic Errors in GitLabEPSS 0.3%CVE-2023-6514HIGH The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of tEPSS 0.3%CVE-2025-13239MEDIUMBdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution submit_checkout behavioral workflowEPSS 0.3%CVE-2026-1599MEDIUMBdtask Bhojon All-In-One Restaurant Management System Checkout placeorder logic errorEPSS 0.3%CVE-2026-1274MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-6601LOWBusiness Logic Errors in GitLabEPSS 0.3%CVE-2025-4037MEDIUMcode-projects ATM Banking moneyWithdraw logic errorEPSS 0.3%