CWE-285
Improper Authorization
About
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Common consequences
- Confidentiality → Read Application Data, Read Files or Directories
- Integrity → Modify Application Data, Modify Files or Directories
- Access Control → Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands
Mitigations
- Architecture and Design: Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking o
- Architecture and Design: Ensure that you perform access control checks related to your business logic. These checks may be different than the access control checks that you apply to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be int
- Architecture and Design: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
- Architecture and Design: For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page. One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages res
- System Configuration, Installation: Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.
CVEs with this weakness
Frequently asked questions
What is CWE-285?
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
How likely is CWE-285 to be exploited?
MITRE rates the likelihood of exploit for CWE-285 as high.
Which platforms does CWE-285 affect?
CWE-285 has been observed on: Not Technology-Specific, Web Server, Database Server.
How many CVEs does Rainforest track for CWE-285?
Rainforest Labs currently tracks 1 published CVEs mapped to CWE-285. They are listed on this page.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
