VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 13 of 506
  • CVE-2020-25282CriSep 11, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020).

  • CVE-2020-5368CriJul 6, 2020
    risk 0.64cvss 9.8epss 0.02

    Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

  • CVE-2018-21251CriJun 19, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.

  • CVE-2020-10620CriMay 14, 2020
    risk 0.64cvss 9.8epss 0.01

    Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.

  • CVE-2020-6823CriApr 24, 2020
    risk 0.64cvss 9.8epss 0.02

    A malicious extension could have called browser.identity.launchWebAuthFlow, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.

  • CVE-2020-11967CriApr 21, 2020
    risk 0.64cvss 9.8epss 0.03

    In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial…

  • CVE-2018-21042CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).

  • CVE-2020-11514CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.09

    The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

  • CVE-2016-11036CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).

  • CVE-2019-12498CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.02

    The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

  • CVE-2020-10257CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.09

    The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe…

  • CVE-2013-3960CriJan 24, 2020
    risk 0.64cvss 9.9epss 0.02

    Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass

  • CVE-2019-19899CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.01

    Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.

  • CVE-2019-15932CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp has Incorrect Access Control.

  • CVE-2019-13547CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.

  • CVE-2019-1010152CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.

  • CVE-2019-1010150CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.

  • CVE-2019-1010149CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.

  • CVE-2019-6580CriJun 12, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions <…

  • CVE-2018-4059CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.02

    An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN…