VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 35 of 464
  • CVE-2020-9457HigMar 6, 2020
    risk 0.57cvss 8.8epss 0.03

    The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.

  • CVE-2020-9456HigMar 6, 2020
    risk 0.57cvss 8.8epss 0.03

    In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.

  • CVE-2020-6188HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.01

    VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing…

  • CVE-2019-12734HigDec 6, 2019
    risk 0.57cvss 8.8epss 0.02

    SiteVision 4 has Incorrect Access Control.

  • CVE-2019-15953HigSep 5, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests.…

  • CVE-2019-14473HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.02

    eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level account can create a new admin level account, read the service messages, clear the system protocol or modify/delete internal programs,…

  • CVE-2019-14544CriAug 2, 2019
    risk 0.57cvss 9.8epss 0.02

    routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

  • CVE-2019-12926HigJul 8, 2019
    risk 0.57cvss 8.8epss 0.01

    MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a number of actions, when logged in as a user, that that user should not have had permission to perform. It was also possible to gain…

  • CVE-2019-2005HigJun 19, 2019
    risk 0.57cvss 8.8epss 0.01

    In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. This could lead to local escalation of privilege on a locked device with no additional execution privileges needed. User interaction…

  • CVE-2019-12274HigJun 6, 2019
    risk 0.57cvss 8.8epss 0.01

    In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive…

  • CVE-2019-11875HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.02

    In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or unauthorized access to certain information. The attack…

  • CVE-2019-0280HigMay 14, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.

  • CVE-2019-10311HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.02

    A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using…

  • CVE-2019-0279HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.01

    ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary authorization checks in all circumstances for an…

  • CVE-2019-10648CriMar 30, 2019
    risk 0.57cvss 9.8epss 0.02

    Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL.

  • CVE-2019-0270HigMar 12, 2019
    risk 0.57cvss 8.8epss 0.01

    ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT,…

  • CVE-2019-5774HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.

  • CVE-2019-0258HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2019-0257HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of…

  • CVE-2019-0243HigJan 8, 2019
    risk 0.57cvss 8.8epss 0.02

    Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.