Broken Object Level Authorization is one of the most common API vulnerabilities — and one of the hardest for signature-based tools to catch.
Some of the most damaging security issues have nothing to do with malformed input — they come from how a workflow was designed.
Insecure Direct Object Reference is simple to understand, simple to introduce, and still one of the most common findings in modern APIs.