Falhas do tipo CWE-264

299 resultados

Controle de acesso e privilégios inadequado

Fraqueza ampla onde o software falha em implementar ou enforçar corretamente controles de acesso, permitindo que usuários acessem recursos, funções ou dados além do que deveriam. O erro está em não validar permissões adequadamente, deixando expostos dados sensíveis ou permitindo que usuários executem ações administrativas sem autorização.

Exemplo

Um endpoint de API que lista dados de outros usuários sem verificar se quem requisita tem permissão; um painel administrativo acessível diretamente via URL sem validação de role; um arquivo de backup com permissões world-readable no servidor.

Como mitigar

Implemente validação de permissões em toda operação sensível (whitelist explícita, não blacklist); use modelos de controle como RBAC ou ABAC; aplique o princípio do menor privilégio; audite regularmente as permissões de arquivos, APIs e diretórios do sistema.

CVE-2020-3426HIGHCisco IOS Software for Cisco Industrial Routers Virtual-LPWA Unauthorized Access VulnerabilityEPSS 2.2%CVE-2023-2255Remote documents loaded without prompt via IFrameEPSS 2.2%CVE-2017-12214A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified CusEPSS 2.2%CVE-2021-36879CRITICALWordPress uListing plugin <= 2.0.5 - Unauthenticated Privilege Escalation vulnerabilityEPSS 2.2%CVE-2017-12251A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interactEPSS 2.2%CVE-2019-12634HIGHCisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Denial of Service VulnerabilityEPSS 2.0%CVE-2018-0398Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct aEPSS 2.0%CVE-2021-27644DolphinScheduler mysql jdbc connector parameters deserialize remote code executionEPSS 1.9%CVE-2018-0130A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an uEPSS 1.9%CVE-2019-1626HIGHCisco SD-WAN Solution Privilege Escalation VulnerabilityEPSS 1.9%CVE-2018-0399Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve EPSS 1.9%CVE-2018-7500A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escaEPSS 1.8%CVE-2021-22661Changing the password on the module webpage does not require the user to type in the current password first. Thus, the password could be chaEPSS 1.8%CVE-2020-3443HIGHCisco Smart Software Manager On-Prem Privilege Escalation VulnerabilityEPSS 1.8%CVE-2020-13922Apache DolphinScheduler (incubating) Permission vulnerabilityEPSS 1.7%CVE-2017-3813A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthEPSS 1.7%CVE-2017-6620A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unautheEPSS 1.6%CVE-2017-12363A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on EPSS 1.6%CVE-2018-0284Cisco Meraki Local Status Page Privilege Escalation VulnerabilityEPSS 1.6%CVE-2018-0437Cisco Umbrella Enterprise Roaming Client and Enterprise Roaming Module Privilege Escalation VulnerabilityEPSS 1.5%