Falhas do tipo CWE-841

56 resultados

Falha na Imposição do Fluxo de Trabalho Esperado

A aplicação não valida ou não garante que as operações sejam executadas na sequência correta que o negócio exige. Um usuário consegue pular etapas, executar ações fora de ordem ou contornar verificações intermediárias, comprometendo a integridade do processo. Isso permite manipulação de workflows críticos como aprovações, pagamentos ou mudanças de estado.

Exemplo

Um sistema de e-commerce que permite um cliente marcar um pedido como 'entregue' antes de ele ter sido 'enviado', ou uma aplicação financeira que deixa confirmar uma transação sem validar se a análise de risco foi completada. O ataque é direto: ir direto ao passo final, ignorando as etapas de segurança.

Como mitigar

Implemente máquinas de estado no backend que validem transições de estado permitidas antes de cada operação (não confie em controles de frontend). Registre e audite todas as mudanças de workflow. Considere usar frameworks ou bibliotecas especializadas em orquestração de processos que reforçam automaticamente o fluxo.

CVE-2022-1667HIGHSecheron SEPCOS Control and Protection RelayEPSS 1.2%CVE-2023-4181MEDIUMSourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflowEPSS 1.1%CVE-2022-2105CRITICALSecheron SEPCOS Control and Protection RelayEPSS 1.0%CVE-2022-2102CRITICALSecheron SEPCOS Control and Protection RelayEPSS 0.9%CVE-2024-51738HIGHSunshine improperly enforces pairing protocol request orderEPSS 0.6%CVE-2024-37296MEDIUMAimeos HTML client vulnerable to digital products download without proper payment status checkEPSS 0.5%CVE-2025-55330MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2025-55332MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-6128MEDIUMspa-cartcms Checkout Page checkout behavioral workflowEPSS 0.5%CVE-2025-58051MEDIUMNextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a tableEPSS 0.5%CVE-2026-43937HIGHYAF.NET: Pre-Handler Authorization Bypass on Admin Pages Enabling Blind SQL Execution via `/Admin/RunSql`EPSS 0.5%CVE-2025-55682MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2025-55337MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-46307HIGHA loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.EPSS 0.5%CVE-2024-0410HIGHImproper Enforcement of Behavioral Workflow in GitLabEPSS 0.5%CVE-2025-48481MEDIUMFreeScout Has Business Logic ErrorsEPSS 0.5%CVE-2025-48476HIGHFreeScout Has Business Logic ErrorsEPSS 0.4%CVE-2026-3130CRITICALImproper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perEPSS 0.4%CVE-2025-2323MEDIUM274056675 springboot-openai-chatgpt Number of Question questionCou updateQuestionCou behavioral workflowEPSS 0.4%CVE-2024-39325MEDIUMaimeos/ai-controller-frontend doesn't reset payment status in basketEPSS 0.4%