Falhas do tipo CWE-693

837 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2024-21412HIGHInternet Shortcut Files Security Feature Bypass VulnerabilityEPSS 99.4%KEVCVE-2013-2465CRITICALUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlierEPSS 98.8%KEVCVE-2019-1003030CRITICALA sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/woEPSS 96.9%KEVCVE-2013-0431MEDIUMUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-EPSS 90.2%KEVCVE-2025-40536HIGHSolarWinds Web Help Desk Security Control Bypass VulnerabilityEPSS 73.6%KEVCVE-2025-0411HIGH7-Zip Mark-of-the-Web Bypass VulnerabilityEPSS 67.1%KEVCVE-2024-34144CRITICALA sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allowsEPSS 48.1%CVE-2024-29988HIGHSmartScreen Prompt Security Feature Bypass VulnerabilityEPSS 44.9%KEVCVE-2018-20251—In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. ThEPSS 31.5%CVE-2024-29510MEDIUMArtifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.EPSS 28.0%CVE-2026-21510HIGHWindows Shell Security Feature Bypass VulnerabilityEPSS 26.2%KEVCVE-2024-31142HIGHx86: Incorrect logic for BTC/SRSO mitigationsEPSS 17.4%CVE-2025-47984HIGHWindows GDI Information Disclosure VulnerabilityEPSS 16.2%CVE-2026-21513HIGHMSHTML Framework Security Feature Bypass VulnerabilityEPSS 15.6%KEVCVE-2024-38213MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 13.6%KEVCVE-2025-68668CRITICALn8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code NodeEPSS 13.2%CVE-2024-30050MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 11.5%CVE-2024-38217MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 10.0%KEVCVE-2021-35556MEDIUMVulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are afEPSS 8.5%CVE-2017-10952—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interactioEPSS 7.2%