VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 243 of 475
  • CVE-2020-6232MedApr 14, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.

  • CVE-2019-14883MedMar 18, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their…

  • CVE-2020-10116MedMar 17, 2020
    risk 0.35cvss 5.3epss 0.01

    cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).

  • CVE-2020-6199MedMar 10, 2020
    risk 0.35cvss 5.4epss 0.00

    The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker…

  • CVE-2019-11761MedJan 8, 2020
    risk 0.35cvss 5.4epss 0.01

    By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects…

  • CVE-2019-15998MedNov 26, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device. The vulnerability is due to a…

  • CVE-2019-18790MedNov 22, 2019
    risk 0.35cvss 6.5epss 0.02

    An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need…

  • CVE-2019-16907MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/nfj/UserFilter?searchQuery=@ URI.

  • CVE-2019-10438MedOct 16, 2019
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2019-16738MedSep 26, 2019
    risk 0.35cvss 5.3epss 0.02

    In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.

  • CVE-2019-15723MedSep 16, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.

  • CVE-2019-14995MedSep 11, 2019
    risk 0.35cvss 5.3epss 0.03

    The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

  • CVE-2019-5463MedSep 9, 2019
    risk 0.35cvss 5.3epss 0.02

    An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

  • CVE-2019-8445MedAug 23, 2019
    risk 0.35cvss 5.3epss 0.03

    Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.

  • CVE-2019-1010304MedJul 15, 2019
    risk 0.35cvss 5.3epss 0.01

    Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control. The impact is: Important. The component is: ProductVariant type in GraphQL API. The attack vector…

  • CVE-2019-10341MedJul 11, 2019
    risk 0.35cvss 6.5epss 0.02

    A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing…

  • CVE-2019-4158MedJun 25, 2019
    risk 0.35cvss 5.4epss 0.01

    IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574.

  • CVE-2019-10308MedApr 30, 2019
    risk 0.35cvss 6.5epss 0.02

    A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers with Overall/Read permission to change the per-job default graph configuration for all users.

  • CVE-2019-10305MedApr 18, 2019
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-9224MedApr 17, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 4 of 5).