VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 33 of 464
  • CVE-2021-33704HigSep 15, 2021
    risk 0.57cvss 8.8epss 0.01

    The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover the vulnerable function, no in-depth system knowledge is required. Once exploited…

  • CVE-2021-22149HigSep 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.

  • CVE-2021-40378HigSep 1, 2021
    risk 0.57cvss 8.1epss 0.15

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.

  • CVE-2021-36232HigAug 31, 2021
    risk 0.57cvss 8.8epss 0.01

    Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

  • CVE-2021-33671HigJul 14, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. The impact of missing authorization could result to abuse of…

  • CVE-2021-27903CriJun 30, 2021
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

  • CVE-2021-24356HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.03

    In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on…

  • CVE-2021-24354HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.01

    A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.

  • CVE-2021-24353HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.01

    The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.

  • CVE-2021-24352HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.01

    The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.

  • CVE-2021-32652HigJun 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1.8.2 allows another authenticated users to access mail metadata of other users. Versions 1.4.3 and 1.8.2 contain patches for this vulnerability; no workarounds…

  • CVE-2021-23014HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might allow Authenticated users with guest privileges to upload…

  • CVE-2021-24184HigApr 5, 2021
    risk 0.57cvss 8.8epss 0.01

    Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

  • CVE-2021-24163HigApr 5, 2021
    risk 0.57cvss 8.8epss 0.01

    The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form –…

  • CVE-2021-21487HigMar 9, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2021-21486HigMar 9, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2020-27220HigJan 14, 2021
    risk 0.57cvss 8.8epss 0.01

    The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target…

  • CVE-2020-16029HigJan 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file.

  • CVE-2020-35745HigJan 7, 2021
    risk 0.57cvss 8.8epss 0.02

    PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

  • CVE-2020-25917HigDec 26, 2020
    risk 0.57cvss 8.8epss 0.01

    Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the…