Falhas do tipo CWE-281

225 resultados

Preservação inadequada de permissões

Quando um programa cria, copia ou modifica arquivos e recursos, mas não mantém ou herda as permissões originais corretamente, permitindo acesso indevido. Isso expõe dados sensíveis ou permite que usuários não autorizados executem operações críticas.

Exemplo

Um backup que copia arquivos de configuração com credenciais, mas muda as permissões para leitura por qualquer usuário do sistema. Ou um instalador que cria diretórios temporários com permissões padrão abertas, deixando senhas de sessão visíveis para outros usuários locais.

Como mitigar

Sempre defina explicitamente permissões restritivas (ex: 0600 para arquivos sensíveis) logo após criar ou copiar arquivos. Use funções seguras da plataforma (chmod, SetSecurityDescriptor) e valide que as permissões foram aplicadas corretamente antes de escrever dados sensíveis.

CVE-2025-43701HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.  This impaEPSS 0.4%CVE-2025-43697HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmnEPSS 0.4%CVE-2024-23464HIGHZscaler bypass with administrative privileges on WindowsEPSS 0.4%CVE-2025-43700HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.  This impacts OmEPSS 0.4%CVE-2025-25711HIGHAn issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/adEPSS 0.4%CVE-2022-41963LOWBigBlueButton contains Improper Preservation of Permissions for whiteboardEPSS 0.4%CVE-2024-9333MEDIUMPermission bypass in M-Files Connector for CopilotEPSS 0.4%CVE-2024-44211HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-EPSS 0.4%CVE-2023-45807MEDIUMOpenSearch Issue with tenant read-only permissionsEPSS 0.4%CVE-2024-44193HIGHA logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to eEPSS 0.4%CVE-2024-33921MEDIUMWordPress ReviewX plugin <= 1.6.21 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-50921MEDIUMInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeaEPSS 0.4%CVE-2024-50924MEDIUMInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the EPSS 0.4%CVE-2024-38361LOWPermissions processing error in spacedbEPSS 0.4%CVE-2024-37575HIGHThe Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phEPSS 0.4%CVE-2024-57698HIGHAn issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, EPSS 0.4%CVE-2026-44947MEDIUMStale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in RancherEPSS 0.4%CVE-2025-32697NONECascading protection is not preventing file reversionsEPSS 0.4%CVE-2023-4996MEDIUMLocal privilege escalation EPSS 0.4%CVE-2022-0330A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code onEPSS 0.4%