VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 194 of 475
  • CVE-2023-30918MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-30913MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-21177MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2023-21173MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21141MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-36702MedJun 7, 2023
    risk 0.36cvss 5.5epss 0.00

    The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+…

  • CVE-2023-30915MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-30914MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-30866MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-30865MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2022-48448MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48447MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48446MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48445MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48444MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48443MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48442MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48441MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48440MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48391MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.