Insecure direct object references (DOR)

Overview

Insecure direct object references (IDORs) occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers can bypass authorisation and access restricted resources.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Frequent

Incidence

How common is this issue?
36%16%
arrow down20%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
1 year6 months
arrow down55%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconSharing and VisibilityiconA01:2021 – Broken Access Controlicon