ベータ Shoulder はベータ版です — 結果が誤っている場合があります。皆さまのフィードバックが次に修正する内容を決定します。 フィードバックを送る
#2 A02:2025

Security Misconfiguration

The application might be vulnerable if it is missing appropriate security hardening or has improperly configured permissions on cloud services.

概要

Rose from #5 to #2 in 2025, with every tested application showing some form of misconfiguration. The increased complexity of modern cloud environments and configurable software has elevated this risk category significantly.

攻撃者がこれを悪用する方法

攻撃パターンを理解することで、より優れた防御を構築できます。これらはセキュリティチームが監視する技術です。

Default credentials

Administrative interfaces or services are left with default usernames and passwords that are publicly known.

検出シグナル: Login attempts using common default credential pairs

Verbose error messages

Detailed error messages expose internal paths, stack traces, or database schemas to attackers.

検出シグナル: Error responses containing internal file paths, SQL queries, or stack traces

Cloud storage exposure

Cloud storage buckets or containers are publicly accessible due to misconfigured access policies.

検出シグナル: Public enumeration of storage resources, anonymous access to sensitive files

予防方法

  • Implement a repeatable hardening process for fast, secure deployment
  • Remove or do not install unused features and frameworks
  • Review and update configurations appropriate to all security notes
  • Use segmented application architecture for effective separation
  • Send security directives to clients (Security Headers)
  • Automate verification of configurations in all environments
  • Use infrastructure as code with security scanning

Shoulder検出付きCWE (6)

これらのCWEにはShoulder検出ルールがあります。クリックして特定の脆弱性と修正を確認してください。

その他のマップされたCWE (14)

これらのCWEはこのカテゴリにマップされていますが、まだShoulderルールがありません。