VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,439)

page 307 of 472
  • CVE-2023-42735MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

  • CVE-2023-40638MedOct 8, 2023
    risk 0.29cvss 4.4epss 0.00

    In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-40636MedOct 8, 2023
    risk 0.29cvss 4.4epss 0.00

    In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed

  • CVE-2023-40631MedOct 8, 2023
    risk 0.29cvss 4.4epss 0.00

    In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

  • CVE-2023-43090MedSep 22, 2023
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.

  • CVE-2023-20833MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: ALPS08017764.

  • CVE-2022-48452MedSep 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-33992MedJul 11, 2023
    risk 0.29cvss 4.5epss 0.00

    The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the…

  • CVE-2022-20544MedDec 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20255MedAug 12, 2022
    risk 0.29cvss 4.4epss 0.00

    In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20182MedJun 15, 2022
    risk 0.29cvss 4.4epss 0.00

    In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2022-20102MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296405.

  • CVE-2022-20100MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06270804.

  • CVE-2022-20098MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06419017.

  • CVE-2022-23621MedFeb 9, 2022
    risk 0.29cvss 5.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through…

  • CVE-2020-10697MedMay 27, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in…

  • CVE-2021-0403MedFeb 26, 2021
    risk 0.29cvss 4.4epss 0.00

    In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID:…

  • CVE-2020-27053MedDec 15, 2020
    risk 0.29cvss 4.4epss 0.00

    In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission bypass due to a missing permission check. This could lead to local information disclosure of the WiFi network name with System execution privileges needed. User interaction is not…

  • CVE-2020-28368MedNov 10, 2020
    risk 0.29cvss 4.4epss 0.00

    Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the…

  • CVE-2020-0135MedJun 11, 2020
    risk 0.29cvss 4.4epss 0.00

    In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…