Falhas do tipo CWE-284

7.151 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2026-83162HIGHVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.3%CVE-2026-83226HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.3%CVE-2026-83223HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Remote). Supported versions that are affected arEPSS 0.3%CVE-2024-13457MEDIUMEvent Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information ExposureEPSS 0.3%CVE-2026-83227HIGHVulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 17.0-26EPSS 0.3%CVE-2026-83156HIGHVulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21EPSS 0.3%CVE-2026-87918MEDIUMWPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX ActionsEPSS 0.3%CVE-2025-56219HIGHIncorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to EPSS 0.3%CVE-2026-83182HIGHVulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools). Supported versions that are affeEPSS 0.3%CVE-2026-83106HIGHVulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that aEPSS 0.3%CVE-2026-14229MEDIUMECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsloadEPSS 0.3%CVE-2026-87249HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2025-64516HIGHGLPI incorrectly authorizes access to documentsEPSS 0.3%CVE-2025-30726MEDIUMVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.3%CVE-2025-37131MEDIUMAuthenticated Arbitrary File Read allows Data Exposure in CLI InterfaceEPSS 0.3%CVE-2025-7864MEDIUMthinkgem JeeSite FileUploadController.java upload unrestricted uploadEPSS 0.3%CVE-2025-56405HIGHAn issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP serviceEPSS 0.3%CVE-2024-43409MEDIUMGhost's improper authentication allows access to member information and actionsEPSS 0.3%CVE-2024-30481MEDIUMWordPress JCH Optimize plugin <= 4.0.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-87142HIGHVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.3%