CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,439)
page 307 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42735 | Med | 0.29 | 4.4 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed | ||
| CVE-2023-40638 | Med | 0.29 | 4.4 | 0.00 | Oct 8, 2023 | In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-40636 | Med | 0.29 | 4.4 | 0.00 | Oct 8, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed | ||
| CVE-2023-40631 | Med | 0.29 | 4.4 | 0.00 | Oct 8, 2023 | In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed | ||
| CVE-2023-43090 | Med | 0.29 | 5.5 | 0.00 | Sep 22, 2023 | A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool. | ||
| CVE-2023-20833 | Med | 0.29 | 4.4 | 0.00 | Sep 4, 2023 | In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: ALPS08017764. | ||
| CVE-2022-48452 | Med | 0.29 | 4.4 | 0.00 | Sep 4, 2023 | In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-33992 | Med | 0.29 | 4.5 | 0.00 | Jul 11, 2023 | The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the… | ||
| CVE-2022-20544 | Med | 0.29 | 4.4 | 0.00 | Dec 16, 2022 | In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20255 | Med | 0.29 | 4.4 | 0.00 | Aug 12, 2022 | In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20182 | Med | 0.29 | 4.4 | 0.00 | Jun 15, 2022 | In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20102 | Med | 0.29 | 4.4 | 0.00 | May 3, 2022 | In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296405. | ||
| CVE-2022-20100 | Med | 0.29 | 4.4 | 0.00 | May 3, 2022 | In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06270804. | ||
| CVE-2022-20098 | Med | 0.29 | 4.4 | 0.00 | May 3, 2022 | In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06419017. | ||
| CVE-2022-23621 | Med | 0.29 | 5.5 | 0.01 | Feb 9, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through… | ||
| CVE-2020-10697 | Med | 0.29 | 4.4 | 0.00 | May 27, 2021 | A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in… | ||
| CVE-2021-0403 | Med | 0.29 | 4.4 | 0.00 | Feb 26, 2021 | In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID:… | ||
| CVE-2020-27053 | Med | 0.29 | 4.4 | 0.00 | Dec 15, 2020 | In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission bypass due to a missing permission check. This could lead to local information disclosure of the WiFi network name with System execution privileges needed. User interaction is not… | ||
| CVE-2020-28368 | Med | 0.29 | 4.4 | 0.00 | Nov 10, 2020 | Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the… | ||
| CVE-2020-0135 | Med | 0.29 | 4.4 | 0.00 | Jun 11, 2020 | In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:… |
- risk 0.29cvss 4.4epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
- risk 0.29cvss 5.5epss 0.00
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
- risk 0.29cvss 4.4epss 0.00
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: ALPS08017764.
- risk 0.29cvss 4.4epss 0.00
In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.5epss 0.00
The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the…
- risk 0.29cvss 4.4epss 0.00
In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.29cvss 4.4epss 0.00
In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.29cvss 4.4epss 0.00
In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…
- risk 0.29cvss 4.4epss 0.00
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296405.
- risk 0.29cvss 4.4epss 0.00
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06270804.
- risk 0.29cvss 4.4epss 0.00
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06419017.
- risk 0.29cvss 5.5epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through…
- risk 0.29cvss 4.4epss 0.00
A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in…
- risk 0.29cvss 4.4epss 0.00
In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID:…
- risk 0.29cvss 4.4epss 0.00
In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission bypass due to a missing permission check. This could lead to local information disclosure of the WiFi network name with System execution privileges needed. User interaction is not…
- risk 0.29cvss 4.4epss 0.00
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the…
- risk 0.29cvss 4.4epss 0.00
In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…