Yuanjing can access application functions, objects, or properties he is not authorized to access
Yuanjing can access application functions, objects, or properties he is not authorized to access
OWASP SCP
81,85,86,131
OWASP ASVS
4.1.3,4.2.1
OWASP AppSensor
ACE1,ACE2,ACE3,ACE4
CAPEC
-
SAFECODE
8,10,11
Implement least privilege, and restrict users to only the functionality, objects and properties that are required to perform their tasks.
NB: the key concept for this card is applying function/object/property authorization controls. See AZ 5 for resource type controls, and AZ 6 for data controls.
OWASP ASVS (4.0): 4.1.3 ,4.2.1
Capec: 122
OWASP SCP: 81,85,86,131
OWASP Appsensor: ACE1,ACE2,ACE3,ACE4
Safecode: 8,10,11
ASVS V4.1 - General Access Control Design
ASVS V4.2 - Operation Level Access Control
No suitable mappings were found.