Falhas do tipo CWE-284

7.073 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2019-10200—A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedulEPSS 1.3%CVE-2023-1834CRITICALRockwell Automation Kinetix 5500 Vulnerable to Open Port ExploitationEPSS 1.3%CVE-2025-2553MEDIUMD-Link DIR-618/DIR-605L formVirtualServ access controlEPSS 1.3%CVE-2025-30433CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15EPSS 1.2%CVE-2024-45489CRITICALArc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (beEPSS 1.2%CVE-2023-36722MEDIUMActive Directory Domain Services Information Disclosure VulnerabilityEPSS 1.2%CVE-2021-24197—wpDataTables < 3.4.2 - Improper Access Control leading to Table Permission TakeoverEPSS 1.2%CVE-2020-13675—Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, whEPSS 1.2%CVE-2024-43600HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2019-10964HIGHMedtronic MiniMed 508 and Paradigm Series Insulin Pumps Improper Access ControlEPSS 1.2%CVE-2020-14312—A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat EnterpriseEPSS 1.2%CVE-2021-40404MEDIUMAn authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-EPSS 1.2%CVE-2022-1553HIGHLeaking password protected articles content due to improper access control in publify/publifyEPSS 1.2%CVE-2021-1389MEDIUMCisco IOS XR and Cisco NX-OS Software IPv6 Access Control List Bypass VulnerabilityEPSS 1.2%CVE-2025-58751LOWVite middleware may serve files starting with the same name with the public directoryEPSS 1.2%CVE-2022-0133MEDIUMImproper Access Control in chocobozzz/peertubeEPSS 1.2%CVE-2022-0203HIGHImproper Access Control in crater-invoice/craterEPSS 1.2%CVE-2023-32632HIGHA command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted EPSS 1.2%CVE-2026-5786HIGHAn Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacEPSS 1.2%CVE-2026-9614HIGHAn Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain aEPSS 1.2%