Impact Factor: 7.337
IC Value 94.33
Articles Viewed: 3,641,069
Articles Downloaded: 1,008,628
Subscription For IAJOME Monthly Alerts
Dr.B.Anuja Beatrice, Aiswarya V R and Johan Finny
Published on : 2026-07-08
Mitigating BOLA Vulnerabilities through Secure by Design Database Scoped Row Level SecurityThe rapid proliferation of microservices architectures across enterprise software ecosystems has fundamentally restructured howapplications expose and govern access to data resources. In these distributed environments, Broken Object Level Authorization(BOLA) has emerged asthe most pervasive and consequential vulnerability class catalogued by OWASP, accounting for a disproportionate share of real-world data breachincidents. Conventional defenses rely on application-layermiddleware filtersapplied by individualdevelopersacrosshundredsof discrete APIroutes—aparadigm that is structurally susceptible to human omission, documentation drift, and static analysis blind spots. This paper conducts a rigorousarchitectural analysisof BOLA'smechanicsand dissectswhycontemporary automated scannersfail to detect it reliably. Wethen proposeand evaluateasecure-by-design remedy: migrating access control enforcement from application code into the database engine itself using native Row-Level Security(RLS) policies. The proposed architecture guarantees that authorization is evaluated atomically at the storage boundary for every query, irrespective ofthe developer's vigilance, eliminating the entire class of BOLA vulnerabilities through structural design rather than procedural discipline.
Keywords—BrokenObjectLevelAuthorization(BOLA),APISecurity,MicroservicesSprawl,Row-LevelSecurity(RLS),Secure-by-Design.
Our journal serves as a platform for academics, researchers, and practitioners in the fields of management and entrepreneurship
Indo Asian Journal of Management and Entreprenuership. All Rights Reserved.