VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 60 of 464
  • CVE-2023-20912HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-20547HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20522HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20508HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20506HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20503HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-42778HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.

  • CVE-2022-42777HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-42776HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.

  • CVE-2022-39102HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39101HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39100HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39099HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39098HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39097HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39096HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39095HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39094HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39093HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39092HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.