VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,748)

page 71 of 88
  • CVE-2026-11500MedJun 8, 2026
    risk 0.26cvss 5.0epss 0.00

    A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization…

  • CVE-2025-66406MedDec 3, 2025
    risk 0.26cvss 5.0epss 0.00

    Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is…

  • CVE-2025-3454MedJun 2, 2025
    risk 0.26cvss 5.0epss 0.00

    This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. …

  • CVE-2023-42973MedApr 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.

  • CVE-2023-42541MedNov 7, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

  • CVE-2023-21505MedMay 4, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.

  • CVE-2023-21461MedMar 16, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.

  • CVE-2023-21429MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.

  • CVE-2022-39905MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.

  • CVE-2022-39883MedNov 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

  • CVE-2022-36838MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.

  • CVE-2022-33722MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.

  • CVE-2022-30757MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

  • CVE-2022-30717MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

  • CVE-2022-24002MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.01

    Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.

  • CVE-2022-22272MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission

  • CVE-2022-22269MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.

  • CVE-2022-22267MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.

  • CVE-2021-25521MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

  • CVE-2021-25460MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.