A01
Broken Access Control
Broken Access Control
Bypass de autorización, IDOR, escalada de privilegios, exposición de objetos.
Authorization bypass, IDOR, privilege escalation, object exposure.
OWASP ZAP · Semgrep · auth probes
A02
Cryptographic Failures
Cryptographic Failures
Algoritmos débiles, claves expuestas, datos sensibles en claro, TLS mal configurado.
Weak algorithms, exposed keys, sensitive data in clear, misconfigured TLS.
Semgrep · gitleaks · OWASP ZAP TLS
A03
Injection
SQLi, NoSQLi, command injection, XSS, LDAP injection, header injection.
SQLi, NoSQLi, command injection, XSS, LDAP injection, header injection.
OWASP ZAP · Semgrep taint · MobSF
A04
Insecure Design
Insecure Design
Threat modeling ausente, patrones inseguros, lógica de negocio sin controles.
Missing threat modeling, insecure patterns, business logic without controls.
ASVS review · architecture audit
A05
Security Misconfiguration
Security Misconfiguration
Defaults inseguros, headers HTTP faltantes, debug expuesto, S3 buckets abiertos.
Insecure defaults, missing HTTP headers, exposed debug, open S3 buckets.
Checkov · OWASP ZAP · Trivy config
A06
Vulnerable Components
Vulnerable Components
Dependencias outdated, CVEs conocidos sin patchear, transitive deps ocultas.
Outdated dependencies, known unpatched CVEs, hidden transitive deps.
Trivy · CycloneDX SBOM · CVSS · EPSS
A07
Auth Failures
Auth Failures
Credenciales débiles, brute-force sin rate limit, session fixation, MFA ausente.
Weak credentials, no rate limit on brute-force, session fixation, missing MFA.
OWASP ZAP · Semgrep auth · session probes
A08
Data Integrity Failures
Data Integrity Failures
Deserialización insegura, dependencias sin firma digital, CI/CD comprometido.
Insecure deserialization, unsigned dependencies, compromised CI/CD.
Trivy · Semgrep · SBOM signing
A09
Logging & Monitoring Failures
Logging & Monitoring Failures
Logs ausentes en eventos críticos, ataques no detectados, sin alerting.
Missing logs on critical events, undetected attacks, no alerting.
Grafana · Loki · audit log review
A10
SSRF
Server-Side Request Forgery, acceso a servicios internos vía URLs externas.
Server-Side Request Forgery, access to internal services via external URLs.
OWASP ZAP · Semgrep ssrf rules