VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 53 of 82
  • CVE-2016-7651MedFeb 20, 2017
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by leveraging the mishandling of an app uninstall.

  • CVE-2026-30959MedMar 10, 2026
    risk 0.33cvss 5.0epss 0.00

    OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects…

  • CVE-2025-67603MedJan 8, 2026
    risk 0.33cvss epss 0.00

    A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This issue affects Foomuuri: from ? before 0.31.

  • CVE-2024-34463MedSep 3, 2024
    risk 0.33cvss 5.1epss 0.01

    BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)

  • CVE-2023-32967MedFeb 2, 2024
    risk 0.33cvss 5.0epss 0.00

    An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected. We have…

  • CVE-2022-45128MedMay 10, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-43465MedMay 10, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-41610MedMay 10, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-21424MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.

  • CVE-2023-21423MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.

  • CVE-2022-36872MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36871MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36870MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36848MedSep 9, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

  • CVE-2018-14637MedNov 30, 2018
    risk 0.33cvss 6.1epss 0.01

    The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.

  • CVE-2024-21179MedJul 16, 2024
    risk 0.32cvss 4.9epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2024-21159MedJul 16, 2024
    risk 0.32cvss 4.9epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2024-21137MedJul 16, 2024
    risk 0.32cvss 4.9epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols…

  • CVE-2023-32482MedJul 20, 2023
    risk 0.32cvss 4.9epss 0.00

    Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious user with privileged access can push policies to unauthorized tenant group.

  • CVE-2022-24894MedFeb 3, 2023
    risk 0.32cvss 5.9epss 0.04

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the…