Excessive data access privileges

Overview

Profiles define how users access objects and data and what they can do within the application. Granting "ViewAllData" or "ViewAllRecords" permissions at the profile level overrides any other record-level access mechanism and may give users excessive data access privileges.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Frequent

Incidence

How common is this issue?
40%25%
arrow down15%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
1 year6 months
arrow down63%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconOrganizational SecurityiconAuthorizationiconA04:2021 – Insecure Designicon