VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 202 of 475
  • CVE-2020-0327MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129151407

  • CVE-2020-0316MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934919

  • CVE-2020-0285MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0284MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0276MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0265MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android…

  • CVE-2020-0372MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0343MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0317MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0314MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934920

  • CVE-2020-0293MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation in Android versions:…

  • CVE-2020-0290MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996866

  • CVE-2020-0289MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996872

  • CVE-2020-0288MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0989MedSep 11, 2020
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files. To exploit this vulnerability,…

  • CVE-2020-0250MedAug 11, 2020
    risk 0.36cvss 5.5epss 0.00

    In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of location data with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0239MedAug 11, 2020
    risk 0.36cvss 5.5epss 0.00

    In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This could lead to local information disclosure from a file (eg. a photo) containing location metadata with no additional execution…

  • CVE-2020-0107MedJul 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0178MedJun 11, 2020
    risk 0.36cvss 5.5epss 0.00

    In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local information disclosure of config flags with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0177MedJun 11, 2020
    risk 0.36cvss 5.5epss 0.00

    In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connection settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…