Falhas do tipo CWE-840

99 resultados

Falhas na Lógica de Negócio

É quando o código implementa corretamente as instruções, mas essas instruções não refletem corretamente as regras de negócio pretendidas. O atacante explora desvios entre o que o sistema *deveria* fazer e o que ele realmente faz para contornar controles, contabilidade ou autorização.

Exemplo

Um carrinho de compras que permite aplica cupom de desconto múltiplas vezes quando deveria aceitar apenas uma; ou um sistema de transferência bancária que não valida se a conta de destino pertence ao mesmo titular, permitindo movimentações não autorizadas entre contas.

Como mitigar

Valide regras de negócio no backend (nunca confie no frontend). Implemente testes que cobram cenários de abuso: cupons reutilizados, limites ultrapassados, estados inválidos. Mantenha auditoria de operações sensíveis e revise regularmente a lógica com especialistas de negócio.

CVE-2023-6566MEDIUMBusiness Logic Errors in microweber/microweberEPSS 0.5%CVE-2025-2323MEDIUM274056675 springboot-openai-chatgpt Number of Question questionCou updateQuestionCou behavioral workflowEPSS 0.5%CVE-2023-3228MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2025-2321MEDIUM274056675 springboot-openai-chatgpt addData logic errorEPSS 0.4%CVE-2024-6446LOWBusiness Logic Errors in GitLabEPSS 0.4%CVE-2024-6577MEDIUMUnclaimed S3 Bucket Usage in pytorch/serveEPSS 0.4%CVE-2025-1908HIGHBusiness Logic Errors in GitLabEPSS 0.4%CVE-2024-1682MEDIUMUnclaimed S3 Bucket Reference in psf/requests DocumentationEPSS 0.4%CVE-2024-45424MEDIUMZoom Workplace Apps - Business Logic ErrorEPSS 0.4%CVE-2018-25104MEDIUMCoinGate Plugin Payment callback.php postProcess logic errorEPSS 0.4%CVE-2026-85030MEDIUMHKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic errorEPSS 0.4%CVE-2025-8991MEDIUMlinlinjava litemall Business Logic express logic errorEPSS 0.3%CVE-2026-8738MEDIUMSanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pay logic errorEPSS 0.3%CVE-2026-1322MEDIUMBusiness Logic Errors in GitLabEPSS 0.3%CVE-2023-6514HIGH The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of tEPSS 0.3%CVE-2025-13239MEDIUMBdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution submit_checkout behavioral workflowEPSS 0.3%CVE-2026-1599MEDIUMBdtask Bhojon All-In-One Restaurant Management System Checkout placeorder logic errorEPSS 0.3%CVE-2026-1274MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-6601LOWBusiness Logic Errors in GitLabEPSS 0.3%CVE-2025-4037MEDIUMcode-projects ATM Banking moneyWithdraw logic errorEPSS 0.3%