Falhas do tipo CWE-285

1.605 resultados

Falha na verificação de autorização

A aplicação não valida (ou valida incorretamente) se um usuário tem permissão para acessar um recurso ou executar uma ação. Um atacante contorna controles de acesso acessando dados, executando operações ou alterando funcionalidades que deveria estar restrito à sua role ou nível de privilégio.

Exemplo

Uma API de admin que exclui usuários verifica se o token é válido, mas nunca confirma se quem faz a requisição é realmente administrador. Um usuário comum envia a mesma requisição e consegue deletar contas — porque a autorização não foi checada.

Como mitigar

Implemente verificações de autorização em todo ponto de acesso sensível: valide permissões não só na camada de apresentação, mas no backend, consulte ACLs/roles antes de cada operação crítica e use frameworks de autorização testados. Nunca confie em verificações do lado do cliente.

CVE-2022-22268MEDIUMIncorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox GuEPSS 0.1%CVE-2024-42032MEDIUMAccess permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.1%CVE-2024-43051MEDIUMImproper Authorization in SPS-HLOSEPSS 0.1%CVE-2026-12065LOWGroww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url schemeEPSS 0.1%CVE-2022-36852LOWImproper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application daEPSS 0.1%CVE-2026-12190MEDIUMGenspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url schemeEPSS 0.1%CVE-2026-12189MEDIUMMoovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url schemeEPSS 0.1%CVE-2024-38425MEDIUMImproper Authorization in PerformanceEPSS 0.1%CVE-2021-25382MEDIUMAn improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contentsEPSS 0.1%CVE-2022-22269MEDIUMKeeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a localEPSS 0.1%CVE-2026-78236HIGHInsecure PIN derivation mechanism in Admin By Request (ABR)EPSS 0.1%CVE-2022-22267MEDIUMImplicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running applicationEPSS 0.1%CVE-2022-22272MEDIUMImproper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE EPSS 0.1%CVE-2022-30757MEDIUMImproper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permissioEPSS 0.1%CVE-2026-0017HIGHIn onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could leadEPSS 0.1%CVE-2021-25460MEDIUMAn improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BEPSS 0.1%CVE-2025-30508MEDIUMImproper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of serviEPSS 0.1%CVE-2022-33722MEDIUMImplicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC addressEPSS 0.1%CVE-2022-33702MEDIUMImproper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass KnoxgEPSS 0.1%CVE-2026-16925HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%