CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,487)
page 240 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20736 | Med | 0.35 | 5.3 | 0.01 | Jun 15, 2022 | A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to… | ||
| CVE-2022-30955 | Med | 0.35 | 6.5 | 0.01 | May 17, 2022 | Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | ||
| CVE-2022-30954 | Med | 0.35 | 6.5 | 0.01 | May 17, 2022 | Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server. | ||
| CVE-2021-44055 | Med | 0.35 | 5.3 | 0.01 | May 5, 2022 | An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability… | ||
| CVE-2022-1511 | Med | 0.35 | 6.5 | 0.01 | Apr 28, 2022 | Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4. | ||
| CVE-2022-0398 | Med | 0.35 | 5.4 | 0.00 | Apr 25, 2022 | The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to… | ||
| CVE-2022-1054 | Med | 0.35 | 5.3 | 0.04 | Apr 18, 2022 | The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name,… | ||
| CVE-2022-0919 | Med | 0.35 | 5.3 | 0.01 | Apr 11, 2022 | The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email… | ||
| CVE-2022-0837 | Med | 0.35 | 5.4 | 0.01 | Apr 4, 2022 | The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment… | ||
| CVE-2022-28134 | Med | 0.35 | 5.4 | 0.01 | Mar 29, 2022 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers. | ||
| CVE-2021-24950 | Med | 0.35 | 5.4 | 0.01 | Mar 14, 2022 | The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before… | ||
| CVE-2022-0932 | Med | 0.35 | 6.5 | 0.01 | Mar 11, 2022 | Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2. | ||
| CVE-2022-26104 | Med | 0.35 | 5.3 | 0.01 | Mar 10, 2022 | SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message. | ||
| CVE-2022-26103 | Med | 0.35 | 5.3 | 0.01 | Mar 10, 2022 | Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks. | ||
| CVE-2022-26102 | Med | 0.35 | 5.4 | 0.00 | Mar 10, 2022 | Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized… | ||
| CVE-2021-25042 | Med | 0.35 | 5.4 | 0.01 | Feb 28, 2022 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address… | ||
| CVE-2022-24594 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address. | ||
| CVE-2022-25355 | Med | 0.35 | 5.3 | 0.01 | Feb 24, 2022 | EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users. | ||
| CVE-2022-0579 | Med | 0.35 | 6.5 | 0.01 | Feb 14, 2022 | Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9. | ||
| CVE-2021-25018 | Med | 0.35 | 5.4 | 0.01 | Feb 14, 2022 | The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could… |
- risk 0.35cvss 5.3epss 0.01
A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to…
- risk 0.35cvss 6.5epss 0.01
Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
- risk 0.35cvss 6.5epss 0.01
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
- risk 0.35cvss 5.3epss 0.01
An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability…
- risk 0.35cvss 6.5epss 0.01
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
- risk 0.35cvss 5.4epss 0.00
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to…
- risk 0.35cvss 5.3epss 0.04
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name,…
- risk 0.35cvss 5.3epss 0.01
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email…
- risk 0.35cvss 5.4epss 0.01
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account balance and payment…
- risk 0.35cvss 5.4epss 0.01
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
- risk 0.35cvss 5.4epss 0.01
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before…
- risk 0.35cvss 6.5epss 0.01
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
- risk 0.35cvss 5.3epss 0.01
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.
- risk 0.35cvss 5.3epss 0.01
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
- risk 0.35cvss 5.4epss 0.00
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized…
- risk 0.35cvss 5.4epss 0.01
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address…
- risk 0.35cvss 5.3epss 0.01
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
- risk 0.35cvss 5.3epss 0.01
EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote unauthenticated attacker to direct the vulnerable version of EC-CUBE to send an Email with some forged reissue-password URL to EC-CUBE users.
- risk 0.35cvss 6.5epss 0.01
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
- risk 0.35cvss 5.4epss 0.01
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could…