Open
Description
Relevant sources:
-
https://cap.cloud.sap/docs/guides/security/aspects#secure-authorization
-
https://cap.cloud.sap/docs/guides/authorization#restrict-annotation
-
CWE-862: Missing Authorization
- The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- CWE-425: Direct Request: The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
-
CWE-842: Placement of User into Incorrect Group
- Subclass: CWE-286: Incorrect User Management
-
CWE-266: Incorrect Privilege Assignment
- A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Metadata
Metadata
Assignees
Labels
No labels