Falhas do tipo CWE-284

7.070 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2021-45034—A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/EPSS 2.3%CVE-2024-29054HIGHMicrosoft Defender for IoT Elevation of Privilege VulnerabilityEPSS 2.3%CVE-2024-29055HIGHMicrosoft Defender for IoT Elevation of Privilege VulnerabilityEPSS 2.3%CVE-2020-24441MEDIUMImproper Access Control in Adobe Acrobat Reader for AndroidEPSS 2.3%CVE-2018-0447—Cisco Email Security Appliance URL Filtering Bypass VulnerabilityEPSS 2.3%CVE-2017-7928—An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway VersionsEPSS 2.3%CVE-2023-28531—ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected vEPSS 2.3%CVE-2019-10925—A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by EPSS 2.3%CVE-2019-9886CRITICALeClass platform allows user to download arbitrary files without authenticationEPSS 2.2%CVE-2022-34255HIGHAdobe Commerce Improper Access Control Privilege escalationEPSS 2.2%CVE-2024-0411MEDIUMDeShang DSMall HTTP GET Request install.php access controlEPSS 2.2%CVE-2019-1660MEDIUMCisco TelePresence Management Suite Simple Object Access Protocol VulnerabilityEPSS 2.2%CVE-2019-1666MEDIUMCisco HyperFlex Unauthenticated Statistics Retrieval VulnerabilityEPSS 2.2%CVE-2019-3927—Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iEPSS 2.2%CVE-2019-7611—A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disEPSS 2.1%CVE-2019-3936—Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port EPSS 2.1%CVE-2021-36036HIGHMagento Commerce Media Gallery Upload Improper Access Control Could Lead To Remote Code ExecutionEPSS 2.1%CVE-2020-7545—A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security EPSS 2.1%CVE-2025-23243MEDIUMNVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability mEPSS 2.1%CVE-2025-15503MEDIUMSangfor Operation and Maintenance Management System common.jsp unrestricted uploadEPSS 2.1%