Falhas do tipo CWE-284

7.074 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2021-23203HIGHImproper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackEPSS 0.9%CVE-2024-31759HIGHAn issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.EPSS 0.9%CVE-2023-22102HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and EPSS 0.9%CVE-2023-36561HIGHAzure DevOps Server Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2019-0041MEDIUMJunos OS: EX4300-MP Series: IP transit traffic can reach the control plane via loopback interface.EPSS 0.9%CVE-2021-41298HIGHECOA BAS controller - Improper Access ControlEPSS 0.9%CVE-2024-11961MEDIUMGuangzhou Huayi Intelligent Technology Jeewms WmOmNoticeHController.java preHandle information disclosureEPSS 0.9%CVE-2022-40798HIGHOcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request withEPSS 0.9%CVE-2021-40416HIGHAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_201EPSS 0.9%CVE-2023-3431MEDIUMImproper Access Control in plantuml/plantumlEPSS 0.9%CVE-2026-58630CRITICALAzure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2021-25672—A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace modulEPSS 0.9%CVE-2024-21145MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). SEPSS 0.9%CVE-2020-3126LOWCisco Webex Meetings Multimedia Viewer VulnerabilityEPSS 0.9%CVE-2023-24468—Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2EPSS 0.9%CVE-2025-0650HIGHOvn: egress acls may be bypassed via specially crafted udp packetEPSS 0.9%CVE-2026-66309CRITICALAzure SQL Database Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-31475MEDIUMWordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerabilityEPSS 0.9%CVE-2026-24306CRITICALAzure Front Door Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2020-25238—A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). ManipulatingEPSS 0.9%