CWE-285
Improper Authorization
Description
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87
CVEs mapped to this weakness (1,626)
page 18 of 82| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-36467 | Hig | 0.49 | 7.5 | 0.01 | Nov 27, 2024 | An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having… | ||
| CVE-2024-38129 | Hig | 0.49 | 7.5 | 0.01 | Oct 8, 2024 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2024-46943 | Hig | 0.49 | 7.5 | 0.01 | Sep 15, 2024 | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information. | ||
| CVE-2024-8509 | Hig | 0.49 | 7.5 | 0.01 | Sep 6, 2024 | A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value… | ||
| CVE-2024-42473 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2024 | OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is… | ||
| CVE-2024-3840 | Hig | 0.49 | 7.5 | 0.01 | Apr 17, 2024 | Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2023-52539 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52359 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-25063 | Hig | 0.49 | 7.5 | 0.01 | Mar 2, 2024 | Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to. | ||
| CVE-2023-5808 | Hig | 0.49 | 7.6 | 0.01 | Dec 5, 2023 | SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that… | ||
| CVE-2023-38220 | Hig | 0.49 | 7.5 | 0.01 | Oct 13, 2023 | Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Authorization vulnerability that could lead in a security feature bypass in a way that an attacker could access unauthorised… | ||
| CVE-2023-0813 | Hig | 0.49 | 7.5 | 0.01 | Sep 15, 2023 | A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows… | ||
| CVE-2023-33020 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE. | ||
| CVE-2023-33019 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE. | ||
| CVE-2023-28584 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA). | ||
| CVE-2023-22428 | Hig | 0.49 | 7.6 | 0.00 | Jul 24, 2023 | Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to… | ||
| CVE-2023-32022 | Hig | 0.49 | 7.6 | 0.01 | Jun 14, 2023 | Windows Server Service Security Feature Bypass Vulnerability | ||
| CVE-2020-36696 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2023 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download… | ||
| CVE-2019-25149 | Hig | 0.49 | 7.6 | 0.01 | Jun 7, 2023 | The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary to site… | ||
| CVE-2022-40536 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. |
- risk 0.49cvss 7.5epss 0.01
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having…
- risk 0.49cvss 7.5epss 0.01
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value…
- risk 0.49cvss 7.5epss 0.01
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is…
- risk 0.49cvss 7.5epss 0.01
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.49cvss 7.5epss 0.00
Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.01
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.
- risk 0.49cvss 7.6epss 0.01
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that…
- risk 0.49cvss 7.5epss 0.01
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Authorization vulnerability that could lead in a security feature bypass in a way that an attacker could access unauthorised…
- risk 0.49cvss 7.5epss 0.01
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows…
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).
- risk 0.49cvss 7.6epss 0.00
Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to…
- risk 0.49cvss 7.6epss 0.01
Windows Server Service Security Feature Bypass Vulnerability
- risk 0.49cvss 7.5epss 0.01
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download…
- risk 0.49cvss 7.6epss 0.01
The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary to site…
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.