[Prev]

2.7 Authorization misconfiguration threats

T71-WrongGrant

Returning grant instead of deny leading to unauthorised access

T72-WrongDeny

Returning deny instead of grant leaving to DOS.

T73-WrongObs

Returning wrong obligations

T74-MissingObs

Missing obligations from authz decisions

T75-OKAC

Attribution of wrong access rights to an otherwise trusted member


[Prev | Next]