Falhas do tipo CWE-284

7.070 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2024-38202HIGHWindows Update Stack Elevation of Privilege VulnerabilityEPSS 1.7%CVE-2019-10962—BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway WEPSS 1.7%CVE-2018-15459MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilityEPSS 1.7%CVE-2022-37393—Zimbra zmslapd arbitrary module loadEPSS 1.7%CVE-2019-6520—Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuEPSS 1.7%CVE-2019-3567—In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder EPSS 1.7%CVE-2025-33056HIGHWindows Local Security Authority (LSA) Denial of Service VulnerabilityEPSS 1.7%CVE-2022-39399LOWVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versionsEPSS 1.6%CVE-2025-4751MEDIUMD-Link DI-7003GV2 index.data information disclosureEPSS 1.6%CVE-2020-9668HIGHAGSService program mishandling symbolic linksEPSS 1.6%CVE-2025-24989HIGHMicrosoft Power Pages Elevation of Privilege VulnerabilityEPSS 1.6%KEVCVE-2021-24583—Timetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot DeletionEPSS 1.6%CVE-2024-49068HIGHMicrosoft SharePoint Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2026-21627CRITICALExtension - tassos.gr - SQL injection and Unauthenticated File Read in Novarain/Tassos Framework v4.10.14 – v6.0.37 for JoomlaEPSS 1.6%CVE-2014-2365—Advantech WebAccess Improper Access ControlEPSS 1.6%CVE-2019-1686MEDIUMCisco ASR 9000 Series Aggregation Services Routers ACL Bypass VulnerabilityEPSS 1.6%CVE-2026-24302HIGHAzure Arc Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2022-34259MEDIUMAdobe Commerce Improper Access Control Security feature bypassEPSS 1.6%CVE-2026-16330MEDIUMD-Link DNS-320 uploadify.php unrestricted uploadEPSS 1.6%CVE-2026-16327MEDIUMD-Link DNS-320 upload.php unrestricted uploadEPSS 1.6%