VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 25 of 82
  • CVE-2023-25074HigJul 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185…

  • CVE-2023-25517HigJul 4, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.

  • CVE-2023-2496HigMay 24, 2023
    risk 0.46cvss 7.1epss 0.01

    The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated…

  • CVE-2023-28973HigApr 17, 2023
    risk 0.46cvss 7.1epss 0.00

    An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Administrative functions…

  • CVE-2023-22636HigFeb 27, 2023
    risk 0.46cvss 7.0epss 0.00

    An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.

  • CVE-2023-23696HigFeb 7, 2023
    risk 0.46cvss 7.0epss 0.00

    Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system.

  • CVE-2023-22480HigJan 14, 2023
    risk 0.46cvss 7.3epss 0.67

    KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This…

  • CVE-2022-41672HigOct 7, 2022
    risk 0.46cvss 8.1epss 0.01

    In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.

  • CVE-2022-36090HigSep 8, 2022
    risk 0.46cvss 8.1epss 0.01

    XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are missing a check for inactive (not yet activated or disabled) users in XWiki, including the REST service. This means a disabled user…

  • CVE-2022-31167HigSep 7, 2022
    risk 0.46cvss 7.1epss 0.01

    XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in…

  • CVE-2022-26773HigMay 26, 2022
    risk 0.46cvss 7.1epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete files for which it does not have permission.

  • CVE-2021-27772HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.01

    Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it.…

  • CVE-2021-25499HigOct 6, 2021
    risk 0.46cvss 7.1epss 0.00

    Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.

  • CVE-2021-25399HigJun 11, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.

  • CVE-2020-9049HigNov 19, 2020
    risk 0.46cvss 7.1epss 0.01

    A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for…

  • CVE-2020-9048HigOct 8, 2020
    risk 0.46cvss 7.1epss 0.01

    A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service…

  • CVE-2020-5362HigJun 10, 2020
    risk 0.46cvss 7.1epss 0.00

    Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to…

  • CVE-2020-3267HigJun 3, 2020
    risk 0.46cvss 7.1epss 0.01

    A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An…

  • CVE-2019-2386HigAug 6, 2019
    risk 0.46cvss 7.1epss 0.01

    After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects MongoDB Server v4.0 versions…

  • CVE-2019-6582HigJun 12, 2019
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions <…