VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 241 of 475
  • CVE-2022-23617MedFeb 9, 2022
    risk 0.35cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. This issue has been patched in…

  • CVE-2021-24993MedFeb 7, 2022
    risk 0.35cvss 6.5epss 0.00

    The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

  • CVE-2021-44795MedJan 27, 2022
    risk 0.35cvss 5.3epss 0.01

    Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitation of this vulnerability might allow a remote attacker to delete permissions…

  • CVE-2021-44794MedJan 27, 2022
    risk 0.35cvss 5.3epss 0.01

    Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive…

  • CVE-2021-44792MedJan 27, 2022
    risk 0.35cvss 5.3epss 0.01

    Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to access the logging interface. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information.

  • CVE-2022-23112MedJan 12, 2022
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2021-24988MedDec 27, 2021
    risk 0.35cvss 5.4epss 0.00

    The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks,…

  • CVE-2021-27858MedDec 15, 2021
    risk 0.35cvss 5.3epss 0.03

    A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some…

  • CVE-2021-43781MedDec 6, 2021
    risk 0.35cvss 6.4epss 0.01

    Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable…

  • CVE-2021-24842MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

  • CVE-2021-24677MedOct 18, 2021
    risk 0.35cvss 5.3epss 0.01

    The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.

  • CVE-2021-42331MedOct 15, 2021
    risk 0.35cvss 5.4epss 0.01

    The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.

  • CVE-2021-39893MedOct 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

  • CVE-2021-24635MedSep 20, 2021
    risk 0.35cvss 5.4epss 0.01

    The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and…

  • CVE-2021-38164MedSep 14, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be…

  • CVE-2021-40088MedAug 25, 2021
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints…

  • CVE-2021-38755MedAug 16, 2021
    risk 0.35cvss 5.3epss 0.01

    Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.

  • CVE-2021-33197MedAug 2, 2021
    risk 0.35cvss 5.3epss 0.02

    In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.

  • CVE-2021-32917MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.

  • CVE-2021-27598MedApr 13, 2021
    risk 0.35cvss 5.3epss 0.01

    SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.