VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 244 of 475
  • CVE-2019-1003099MedApr 4, 2019
    risk 0.35cvss 6.5epss 0.02

    A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003093MedApr 4, 2019
    risk 0.35cvss 6.5epss 0.02

    A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003085MedApr 4, 2019
    risk 0.35cvss 6.5epss 0.02

    A missing permission check in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003047MedMar 28, 2019
    risk 0.35cvss 6.5epss 0.02

    A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003037MedMar 8, 2019
    risk 0.35cvss 6.5epss 0.01

    An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2019-9482MedMar 1, 2019
    risk 0.35cvss 5.3epss 0.01

    In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

  • CVE-2018-18004MedJan 3, 2019
    risk 0.35cvss 5.3epss 0.01

    Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter.

  • CVE-2018-15429MedOct 5, 2018
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to a lack of proper input and authorization of HTTP requests. An…

  • CVE-2011-4183MedJun 13, 2018
    risk 0.35cvss 6.5epss 0.01

    A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.

  • CVE-2018-10207MedApr 25, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricted, via vectors involving page-by-page access to a document in SWF format.

  • CVE-2018-2413MedApr 10, 2018
    risk 0.35cvss 5.4epss 0.01

    SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2018-1000022MedFeb 9, 2018
    risk 0.35cvss 5.3epss 0.02

    Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulnerability in JSONRPC interface that can result in Bitcoin theft, if the user's wallet is not password protected. This attack appear to be exploitable via The…

  • CVE-2017-9513MedJan 29, 2018
    risk 0.35cvss 5.4epss 0.01

    Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have…

  • CVE-2017-1000105MedOct 5, 2017
    risk 0.35cvss 5.3epss 0.01

    The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.

  • CVE-2017-8217MedApr 25, 2017
    risk 0.35cvss 5.3epss 0.01

    TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface.

  • CVE-2026-77701MedAug 28, 2026
    risk 0.34cvss 5.3epss 0.00

    The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.

  • CVE-2026-12514MedAug 28, 2026
    risk 0.34cvss 5.3epss 0.00

    The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an…

  • CVE-2026-81276MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

  • CVE-2026-81274MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

  • CVE-2026-77694MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.