VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 39 of 82
  • CVE-2024-38425MedOct 7, 2024
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while sending implicit broadcast containing APP launch information.

  • CVE-2023-41819MedMay 3, 2024
    risk 0.40cvss 6.1epss 0.00

    A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers. 

  • CVE-2024-21039MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-21035MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-21031MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-21026MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-21018MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2023-44125MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, if it had access to app…

  • CVE-2023-44123MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if it had access to app…

  • CVE-2023-29152MedJun 7, 2023
    risk 0.40cvss 6.2epss 0.00

    By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

  • CVE-2023-21440MedFeb 9, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.

  • CVE-2022-39890MedNov 9, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

  • CVE-2022-36837MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.

  • CVE-2022-33702MedJul 12, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.

  • CVE-2022-30722MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

  • CVE-2022-22268MedJan 10, 2022
    risk 0.40cvss 6.1epss 0.00

    Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.

  • CVE-2021-25382MedApr 23, 2021
    risk 0.40cvss 6.1epss 0.00

    An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.

  • CVE-2019-1003003HigJan 22, 2019
    risk 0.40cvss 7.2epss 0.02

    An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never…

  • CVE-2026-45415MedAug 6, 2026
    risk 0.39cvss 6.0epss 0.00

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rendering or mutating…

  • CVE-2026-70472HigAug 4, 2026
    risk 0.39cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs…