Falhas do tipo CWE-640

219 resultados

Mecanismo fraco de recuperação de senha

A aplicação oferece um fluxo de recuperação de senha (esqueci minha senha) que é facilmente contornável ou previsível. Um atacante pode adivinhar perguntas de segurança, interceptar links de reset, reusar tokens, ou explorar validações fracas para assumir contas alheias sem conhecer a senha original.

Exemplo

Um site envia um link de reset de senha por e-mail, mas o token nunca expira e é simplesmente o ID do usuário codificado em base64. Um atacante pode reutilizar tokens antigos ou gerar novos para qualquer usuário, resetando suas senhas à vontade.

Como mitigar

Implemente tokens de reset com alta entropia, validade curta (15-30 min), uso único, e vinculação ao IP/sessão. Valide a identidade antes do reset (OTP, e-mail de confirmação, desafio adaptativo). Registre e monitore tentativas anormais de recuperação.

CVE-2023-28202This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS VentEPSS 0.2%CVE-2026-82487MEDIUMBeetel 450TC3 password recoveryEPSS 0.2%CVE-2024-12604MEDIUMImproper Authentication in Tapandsign Technologies Tap and Sign AppEPSS 0.2%CVE-2026-34198MEDIUMCoolify: Password reset link poisoning via X-Forwarded-Host header spoofingEPSS 0.2%CVE-2026-4136MEDIUMMembership Plugin – Restrict Content <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirectEPSS 0.2%CVE-2024-32642HIGHHost header poisoning allows account takeover via password reset emailEPSS 0.2%CVE-2026-62486MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2026-64635MEDIUMImproper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attEPSS 0.2%CVE-2026-60648HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2023-34357HIGHSoar Cloud Ltd. HR Portal - Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.2%CVE-2026-60646HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2026-60650HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2025-36579MEDIUMDell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to theEPSS 0.2%CVE-2026-46894HIGHVulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affecteEPSS 0.2%CVE-2025-55030MEDIUMContent-Disposition headers incorrectly ignored for some MIME typesEPSS 0.2%CVE-2026-62517MEDIUMVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2026-60658HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.1%CVE-2025-65203HIGHKeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directivEPSS 0.1%CVE-2025-61977HIGHAutomationDirect Productivity Suite Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.1%