VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 422 of 464
  • CVE-2022-20537LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In createDialog of WifiScanModeActivity.java, there is a possible way for a Guest user to enable location-sensitive settings due to a missing permission check. This could lead to local escalation of privilege from the Guest user with no additional execution privileges needed.…

  • CVE-2022-20536LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20533LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20519LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-42903LowNov 17, 2022
    risk 0.21cvss 3.3epss 0.00

    Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.

  • CVE-2022-40309MedNov 15, 2022
    risk 0.21cvss 4.3epss 0.01

    Users with write permissions to a repository can delete arbitrary directories.

  • CVE-2022-20446LowNov 8, 2022
    risk 0.21cvss 3.3epss 0.00

    In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2022-43431MedOct 19, 2022
    risk 0.21cvss 4.3epss 0.00

    Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-43427MedOct 19, 2022
    risk 0.21cvss 4.3epss 0.00

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-43413MedOct 19, 2022
    risk 0.21cvss 4.3epss 0.01

    Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-41233MedSep 21, 2022
    risk 0.21cvss 4.3epss 0.01

    Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given job, if the optional Run/Artifacts permission is enabled.

  • CVE-2022-41230MedSep 21, 2022
    risk 0.21cvss 4.3epss 0.01

    Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for…

  • CVE-2022-2377MedAug 22, 2022
    risk 0.21cvss 4.3epss 0.00

    The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog

  • CVE-2022-2841LowAug 22, 2022
    risk 0.21cvss 2.7epss 0.05

    A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the…

  • CVE-2022-20340LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20336LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to local information disclosure of applications allow-listed to use the network during VPN lockdown mode with no additional execution privileges needed. User…

  • CVE-2022-20335LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20328LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20321LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2022-20315LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…