VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 385 of 464
  • CVE-2020-13319MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

  • CVE-2020-2272MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2020-2267MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to gain access to some metadata of any arbitrary files on the Jenkins controller.

  • CVE-2020-2260MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.

  • CVE-2020-6273MedAug 12, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.

  • CVE-2020-2216MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified username and password.

  • CVE-2020-2204MedJul 2, 2020
    risk 0.28cvss 5.4epss 0.01

    A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.

  • CVE-2020-15412MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.

  • CVE-2020-13266MedJun 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions

  • CVE-2020-12700MedMay 13, 2020
    risk 0.28cvss 4.3epss 0.01

    The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query.

  • CVE-2020-12698MedMay 13, 2020
    risk 0.28cvss 4.3epss 0.01

    The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.

  • CVE-2020-6256MedMay 12, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check.

  • CVE-2020-6233MedApr 14, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system.

  • CVE-2019-20407MedMar 17, 2020
    risk 0.28cvss 4.3epss 0.01

    The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.

  • CVE-2020-6204MedMar 10, 2020
    risk 0.28cvss 4.3epss 0.01

    The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number,…

  • CVE-2020-9455MedMar 6, 2020
    risk 0.28cvss 4.3epss 0.01

    The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.

  • CVE-2020-8811MedFeb 7, 2020
    risk 0.28cvss 4.3epss 0.01

    ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.

  • CVE-2020-7993MedFeb 3, 2020
    risk 0.28cvss 4.3epss 0.01

    Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.

  • CVE-2019-15013MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.01

    The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue…

  • CVE-2019-16571MedDec 17, 2019
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.