VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 199 of 475
  • CVE-2022-20301MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20300MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20299MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20298MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20296MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20295MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20294MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20284MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone accounts with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20263MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20259MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android…

  • CVE-2021-0735MedAug 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-20352MedAug 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-20225MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-21764MedJul 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID:…

  • CVE-2022-21763MedJul 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID:…

  • CVE-2022-20206MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not needed for…

  • CVE-2022-20200MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20172MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-31752MedJun 13, 2022
    risk 0.36cvss 5.5epss 0.00

    Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.

  • CVE-2022-21749MedJun 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511058; Issue ID:…