Falhas do tipo CWE-284

7.169 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2025-64706MEDIUMTypebot IDOR Vulnerability: Unauthorized API Token Deletion and ExposureEPSS 0.2%CVE-2025-53041MEDIUMVulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are EPSS 0.2%CVE-2025-13443MEDIUMmacrozheng mall delete access controlEPSS 0.2%CVE-2025-53060MEDIUMVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are EPSS 0.2%CVE-2023-34403MEDIUMMercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to inteEPSS 0.2%CVE-2026-60832MEDIUMVulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions thEPSS 0.2%CVE-2025-5962HIGHRhel-lightspeed: improper access control in lightspeed history management allows local privilege manipulationEPSS 0.2%CVE-2024-0374MEDIUMViews for WPForms <= 3.2.2 - Cross-Site Request Forgery via create_viewEPSS 0.2%CVE-2026-83111HIGHVulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions thatEPSS 0.2%CVE-2025-50850HIGHAn issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verificatiEPSS 0.2%CVE-2024-0373MEDIUMViews for WPForms <= 3.2.2 - Cross-Site Request Forgery via save_viewEPSS 0.2%CVE-2026-19625MEDIUMIBM Enterprise Build of Quarkus is affected by multiple vulnerabilitiesEPSS 0.2%CVE-2026-62482MEDIUMVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.2%CVE-2026-61221MEDIUMVulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs). Supported versions that are affected EPSS 0.2%CVE-2026-83077MEDIUMVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.2%CVE-2026-51892MEDIUMinfiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.EPSS 0.2%CVE-2026-61260MEDIUMVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.2%CVE-2026-71165MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.2%CVE-2026-61252MEDIUMVulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kong Payroll). Supported versions that areEPSS 0.2%CVE-2026-60154MEDIUMVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.2%