Fallos del tipo CWE-264

288 resultados

Controle de acesso e privilégios inadequado

A aplicação não valida ou não implementa corretamente as permissões necessárias para acessar recursos sensíveis, permitindo que usuários realizem operações além do seu nível de privilégio autorizado. Isso pode expor dados confidenciais, modificar informações críticas ou comprometer a integridade do sistema.

Ejemplo

Um usuário comum consegue acessar diretamente uma rota administrativa (/admin/users) porque o backend não verifica se ele é administrador antes de executar a ação, apenas confiando que não tentaria; ou um processo de aplicação roda como root quando precisaria rodar como usuário não-privilegiado, ampliando o impacto de qualquer falha.

Cómo mitigar

Implemente validação de privilégios em todas as operações sensíveis (verificar permissões no servidor, nunca só no cliente), use princípio do menor privilégio (processos e contas com permissões mínimas necessárias), e mantenha matriz de controle de acesso (RBAC ou ABAC) consistente e auditada.

CVE-2020-3426HIGHCisco IOS Software for Cisco Industrial Routers Virtual-LPWA Unauthorized Access VulnerabilityEPSS 2.2%CVE-2019-1855HIGHCisco Jabber for Windows DLL Preloading VulnerabilityEPSS 2.2%CVE-2017-12214A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified CusEPSS 2.2%CVE-2021-36879CRITICALWordPress uListing plugin <= 2.0.5 - Unauthenticated Privilege Escalation vulnerabilityEPSS 2.2%CVE-2017-12251A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interactEPSS 2.2%CVE-2018-0398Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct aEPSS 2.1%CVE-2019-12634HIGHCisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Denial of Service VulnerabilityEPSS 2.0%CVE-2018-0130A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an uEPSS 1.9%CVE-2019-1626HIGHCisco SD-WAN Solution Privilege Escalation VulnerabilityEPSS 1.9%CVE-2018-0399Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve EPSS 1.9%CVE-2018-7500A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escaEPSS 1.9%CVE-2021-27644DolphinScheduler mysql jdbc connector parameters deserialize remote code executionEPSS 1.9%CVE-2020-3443HIGHCisco Smart Software Manager On-Prem Privilege Escalation VulnerabilityEPSS 1.8%CVE-2020-13922Apache DolphinScheduler (incubating) Permission vulnerabilityEPSS 1.7%CVE-2017-3813A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthEPSS 1.7%CVE-2017-6620A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unautheEPSS 1.6%CVE-2017-12363A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on EPSS 1.6%CVE-2018-0284Cisco Meraki Local Status Page Privilege Escalation VulnerabilityEPSS 1.6%CVE-2018-0437Cisco Umbrella Enterprise Roaming Client and Enterprise Roaming Module Privilege Escalation VulnerabilityEPSS 1.5%CVE-2018-0463Cisco Network Services Orchestrator Network Plug and Play Information Disclosure VulnerabilityEPSS 1.5%