VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 242 of 475
  • CVE-2020-36287MedApr 9, 2021
    risk 0.35cvss 5.3epss 0.09

    The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions…

  • CVE-2021-22513MedApr 8, 2021
    risk 0.35cvss 6.5epss 0.01

    Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow access without permission checks.

  • CVE-2020-36238MedApr 1, 2021
    risk 0.35cvss 5.3epss 0.02

    The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions…

  • CVE-2021-21632MedMar 30, 2021
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

  • CVE-2021-27656MedMar 18, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

  • CVE-2020-10858MedFeb 5, 2021
    risk 0.35cvss 5.3epss 0.01

    Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.

  • CVE-2020-29604MedJan 29, 2021
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues) to use the COPY group action to create a clone, including all bugnotes and attachments, of any private issue (i.e., one having…

  • CVE-2021-23123MedJan 12, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.

  • CVE-2020-5022MedJan 8, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658.

  • CVE-2020-26408MedDec 11, 2020
    risk 0.35cvss 5.3epss 0.01

    A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

  • CVE-2020-14205MedDec 8, 2020
    risk 0.35cvss 5.3epss 0.01

    The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.

  • CVE-2020-14185MedOct 15, 2020
    risk 0.35cvss 5.3epss 0.02

    Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version…

  • CVE-2020-2242MedSep 1, 2020
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.

  • CVE-2020-15109MedAug 4, 2020
    risk 0.35cvss 5.3epss 0.01

    In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order…

  • CVE-2018-21257MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.

  • CVE-2020-3245MedJun 18, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to create arbitrary user accounts. The vulnerability is due to the lack of authorization controls in the web application. An attacker…

  • CVE-2019-20801MedMay 18, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a…

  • CVE-2020-1996MedMay 13, 2020
    risk 0.35cvss 5.3epss 0.01

    A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries…

  • CVE-2020-6212MedApr 24, 2020
    risk 0.35cvss 5.4epss 0.01

    Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing…

  • CVE-2020-6232MedApr 14, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.