VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 5 of 82
  • CVE-2024-25106CriFeb 8, 2024
    risk 0.59cvss 9.1epss 0.00

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user…

  • CVE-2023-39403CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39402CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39401CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39400CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39399CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39398CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2022-38375CriFeb 16, 2023
    risk 0.59cvss 9.1epss 0.01

    An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.

  • CVE-2022-47409CriDec 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction…

  • CVE-2022-27583CriOct 31, 2022
    risk 0.59cvss 9.1epss 0.01

    A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.

  • CVE-2022-31247CriSep 7, 2022
    risk 0.59cvss 9.1epss 0.01

    An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner…

  • CVE-2022-26857CriMay 26, 2022
    risk 0.59cvss 9.0epss 0.01

    Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.

  • CVE-2021-28506CriJan 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.

  • CVE-2021-28501CriJan 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

  • CVE-2021-28500CriJan 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

  • CVE-2021-41974CriOct 8, 2021
    risk 0.59cvss 9.1epss 0.01

    Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.

  • CVE-2021-36029CriSep 1, 2021
    risk 0.59cvss 9.1epss 0.02

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.

  • CVE-2021-32523CriJul 7, 2021
    risk 0.59cvss 9.1epss 0.01

    Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2019-19723criSep 4, 2020
    risk 0.59cvss epss 0.00

    All versions of `passport-cognito` are vulnerable to Improper Authorization. The package fails to properly scope the variables containing authorization information, such as access token, refresh token and ID token. This causes a race condition where simultaneous authenticated…

  • CVE-2019-17631CriOct 17, 2019
    risk 0.59cvss 9.1epss 0.02

    From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.