Back to Labs
Weakness (CWE)

CWE-863

Incorrect Authorization

About

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Common consequences

  • Confidentiality → Read Application Data, Read Files or Directories
  • Integrity → Modify Application Data, Modify Files or Directories
  • Access Control → Gain Privileges or Assume Identity, Bypass Protection Mechanism
  • Confidentiality, Integrity, Availability → Execute Unauthorized Code or Commands
  • Availability → DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other)

Mitigations

  • Architecture and Design: Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from a
  • Architecture and Design: Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be
  • Architecture and Design: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
  • Architecture and Design: For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page. One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages res
  • System Configuration, Installation: Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.

CVEs with this weakness

Frequently asked questions

What is CWE-863?

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

How likely is CWE-863 to be exploited?

MITRE rates the likelihood of exploit for CWE-863 as high.

Which platforms does CWE-863 affect?

CWE-863 has been observed on: Web Server, Database Server, Not Technology-Specific.

How many CVEs does Rainforest track for CWE-863?

Rainforest Labs currently tracks 1 published CVEs mapped to CWE-863. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.