CWE一覧に戻る
CWE-269

不適切な特権管理

Improper Privilege Management
脆弱性 レビュー中
JA

この製品では、アクターに対する権限の割り当て、変更、追跡、チェックが適切に行われないため、そのアクターに意図しない支配領域が生じます。

EN

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Scope: Access Control / Impact: Gain Privileges or Assume Identity
Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Follow the principle of least privilege when assigning access rights to entities in a software system.
Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
MITRE公式ページ — CWE-269