The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
For each and every data access, ensure that the user has sufficient privilege to access the record that is being requested.
Make sure that the key that is used in the lookup of a specific user's record is not controllable externally by the user or that any tampering can be detected.
Use encryption in order to make it more difficult to guess other legitimate values of the key or associate a digital signature with the key so that the server can verify that there has been no tampering.
Our security experts can help you identify and remediate CWE-639 vulnerabilities in your codebase.
Get Security Assessment