VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 103 of 464
  • CVE-2023-36815HigJul 3, 2023
    risk 0.47cvss 7.3epss 0.01

    Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the…

  • CVE-2021-4350HigJun 7, 2023
    risk 0.47cvss 7.2epss 0.01

    The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated…

  • CVE-2022-36226HigAug 26, 2022
    risk 0.47cvss 7.2epss 0.01

    SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.

  • CVE-2022-20137HigJun 15, 2022
    risk 0.47cvss 7.3epss 0.00

    In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for…

  • CVE-2022-20126HigJun 15, 2022
    risk 0.47cvss 7.3epss 0.00

    In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for…

  • CVE-2022-27948HigMar 27, 2022
    risk 0.47cvss 7.2epss 0.01

    Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a fixed sequence of approximately one hundred symbols. NOTE: the vendor's perspective is that the behavior is as intended

  • CVE-2021-46075HigJan 6, 2022
    risk 0.47cvss 7.2epss 0.03

    A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.

  • CVE-2021-40853HigDec 17, 2021
    risk 0.47cvss 7.2epss 0.01

    TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to…

  • CVE-2021-31384HigOct 19, 2021
    risk 0.47cvss 7.2epss 0.01

    Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can…

  • CVE-2020-20698HigJul 30, 2021
    risk 0.47cvss 7.2epss 0.02

    A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of a PHP file.

  • CVE-2021-33676HigJul 14, 2021
    risk 0.47cvss 7.2epss 0.01

    A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.

  • CVE-2020-20444HigJun 16, 2021
    risk 0.47cvss 7.2epss 0.01

    Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

  • CVE-2021-24146HigMar 18, 2021
    risk 0.47cvss 7.5epss 0.31

    Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

  • CVE-2020-14987HigMar 11, 2021
    risk 0.47cvss 7.2epss 0.04

    An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker…

  • CVE-2019-18581HigMar 18, 2020
    risk 0.47cvss 7.2epss 0.04

    Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may…

  • CVE-2019-19937HigMar 16, 2020
    risk 0.47cvss 7.2epss 0.01

    In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."

  • CVE-2012-6614HigFeb 19, 2020
    risk 0.47cvss 7.2epss 0.03

    D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.

  • CVE-2019-0349HigAug 14, 2019
    risk 0.47cvss 7.2epss 0.01

    SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to…

  • CVE-2019-12168HigMay 17, 2019
    risk 0.47cvss 7.2epss 0.04

    Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen.

  • CVE-2018-15329HigDec 20, 2018
    risk 0.47cvss 7.2epss 0.01

    On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed…