VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 506 of 506
  • CVE-2022-30594HigMay 12, 2022
    risk 0.00cvss 7.8epss 0.01

    The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.

  • CVE-2022-21718LowMar 22, 2022
    risk 0.00cvss 3.4epss 0.01

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth…

  • CVE-2022-0756MedMar 7, 2022
    risk 0.00cvss 6.5epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2022-0755MedMar 7, 2022
    risk 0.00cvss 4.3epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2022-0726MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-21707MedJan 21, 2022
    risk 0.00cvss 6.3epss 0.01

    wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…

  • CVE-2014-6292Oct 3, 2014
    risk 0.00cvss —epss 0.01

    The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.

  • CVE-2014-0167Apr 15, 2014
    risk 0.00cvss —epss 0.02

    The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using…

  • CVE-2012-4245Aug 31, 2012
    risk 0.00cvss —epss 0.05

    The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

  • CVE-2010-4408Dec 6, 2010
    risk 0.00cvss —epss 0.02

    Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a…

  • CVE-2010-1617Apr 29, 2010
    risk 0.00cvss —epss 0.02

    user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

  • CVE-2009-3781Oct 26, 2009
    risk 0.00cvss —epss 0.02

    The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.

  • CVE-2009-2282Jul 1, 2009
    risk 0.00cvss —epss 0.00

    The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain…

  • CVE-2008-6548Mar 30, 2009
    risk 0.00cvss —epss 0.01

    The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

  • CVE-2006-4483Aug 31, 2006
    risk 0.00cvss —epss 0.03

    The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

  • CVE-2006-3935Jul 31, 2006
    risk 0.00cvss —epss 0.02

    system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3)…

  • CVE-2005-3623Dec 31, 2005
    risk 0.00cvss —epss 0.03

    nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.