VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 18 of 464
  • CVE-2023-41296CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.

  • CVE-2023-3124HigJun 7, 2023
    risk 0.59cvss 8.8epss 0.23

    The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level…

  • CVE-2021-4357CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers…

  • CVE-2021-4356CriJun 7, 2023
    risk 0.59cvss 9.0epss 0.02

    The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action.…

  • CVE-2023-26957CriMar 9, 2023
    risk 0.59cvss 9.1epss 0.01

    onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

  • CVE-2022-39811CriJan 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access to resources, it allows an attacker to view pages that are not allowed, and modify the system…

  • CVE-2022-35293CriAug 10, 2022
    risk 0.59cvss 9.1epss 0.01

    Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

  • CVE-2022-1521CriJun 24, 2022
    risk 0.59cvss 9.1epss 0.01

    LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.

  • CVE-2020-4926CriMay 24, 2022
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.

  • CVE-2022-26546CriMar 31, 2022
    risk 0.59cvss 9.1epss 0.01

    Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.

  • CVE-2022-0492HigKEVMar 3, 2022
    risk 0.59cvss 7.8epss 0.06

    A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation…

  • CVE-2021-28506CriJan 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.

  • CVE-2021-39231CriNov 19, 2021
    risk 0.59cvss 9.1epss 0.02

    In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

  • CVE-2020-25366CriNov 4, 2021
    risk 0.59cvss 9.1epss 0.02

    An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

  • CVE-2021-41729CriSep 30, 2021
    risk 0.59cvss 9.1epss 0.01

    BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.

  • CVE-2020-25359CriAug 20, 2021
    risk 0.59cvss 9.1epss 0.02

    An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext…

  • CVE-2020-19038CriJul 12, 2021
    risk 0.59cvss 9.1epss 0.01

    File Deletion vulnerability in Halo 0.4.3 via delBackup.

  • CVE-2018-10866CriMay 26, 2021
    risk 0.59cvss 9.1epss 0.01

    It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him.

  • CVE-2020-4669CriMay 17, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the…

  • CVE-2021-26990CriMar 19, 2021
    risk 0.59cvss 9.1epss 0.02

    Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.