Falhas do tipo CWE-610

96 resultados

Controle de acesso inadequado

É quando o software falha em validar corretamente quem pode acessar um recurso, função ou dado. O código não verifica permissões de forma robusta, permitindo que usuários não autorizados façam operações que não deveriam poder fazer.

Exemplo

Uma API que lista pedidos de um cliente usando apenas o ID do pedido na URL (exemplo.com/pedidos/123) sem verificar se o usuário logado é dono daquele pedido. Um atacante muda o ID para 124 e acessa dados de outro cliente.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis — valide não apenas se o usuário está autenticado, mas se ele tem permissão específica para aquele recurso. Use listas de controle de acesso (ACL) ou políticas de autorização centralizadas e revise-as regularmente.

CVE-2023-21097HIGHIn toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escEPSS 0.2%CVE-2022-44747LOWLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2022-20515MEDIUMIn onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to aEPSS 0.2%CVE-2022-46868MEDIUMLocal privilege escalation during recovery due to improper soft link handling. The following products are affected: Acronis Cyber Protect HoEPSS 0.2%CVE-2026-28721HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2026-28722HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2024-13177MEDIUMSymlink Following in Netskope Client Postinstall ScriptEPSS 0.1%CVE-2025-48963HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.1%CVE-2022-20550HIGHIn Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local esEPSS 0.1%CVE-2023-20964HIGHIn multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local EPSS 0.1%CVE-2022-20199MEDIUMIn multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local infoEPSS 0.1%CVE-2024-49722MEDIUMIn showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to EPSS 0.1%CVE-2025-48654HIGHIn onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to lEPSS 0.1%CVE-2024-49728MEDIUMIn generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lEPSS 0.1%CVE-2025-0082MEDIUMIn multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confuseEPSS 0.1%CVE-2026-21810MEDIUMHCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checkingEPSS 0.1%