VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 189 of 475
  • CVE-2023-40650MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40649MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40648MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40647MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40646MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40645MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40644MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40643MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40642MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40641MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-40640MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-40639MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-40637MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-40633MedOct 8, 2023
    risk 0.36cvss 5.5epss 0.00

    In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-21291MedOct 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-45245MedOct 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 36119.

  • CVE-2023-45243MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-45242MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-45240MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739.

  • CVE-2023-44214MedOct 5, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739.