VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 201 of 475
  • CVE-2021-0641MedAug 17, 2021
    risk 0.36cvss 5.5epss 0.00

    In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2021-0654MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information disclosure from locked profiles with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-0597MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2021-0518MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0554MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android…

  • CVE-2021-0521MedJun 21, 2021
    risk 0.36cvss 5.5epss 0.00

    In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of cross-user permissions with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0428MedApr 13, 2021
    risk 0.36cvss 5.5epss 0.00

    In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2020-29621MedApr 2, 2021
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to bypass Privacy preferences.

  • CVE-2020-7343MedJan 18, 2021
    risk 0.36cvss 5.5epss 0.00

    Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The product would continue to function with out-of-date detection files.

  • CVE-2020-27032MedDec 15, 2020
    risk 0.36cvss 5.5epss 0.00

    In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0497MedDec 15, 2020
    risk 0.36cvss 5.5epss 0.00

    In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0477MedDec 15, 2020
    risk 0.36cvss 5.5epss 0.00

    In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the current network configuration with no additional execution privileges needed.…

  • CVE-2020-0468MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2020-27349MedDec 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.

  • CVE-2020-0454MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of the current SSID with User execution privileges needed. User interaction is not needed for…

  • CVE-2020-0448MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to track an account across devices, with no…

  • CVE-2020-0437MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0419MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2020-0378MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9…

  • CVE-2020-0246MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…