VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 61 of 464
  • CVE-2022-39091HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39090HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-20451HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20450HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-39111HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39110HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39109HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39108HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39107HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.

  • CVE-2022-39080HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

  • CVE-2022-38698HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

  • CVE-2022-38670HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

  • CVE-2022-38669HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

  • CVE-2022-2985HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

  • CVE-2022-20434HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242244028

  • CVE-2022-20433HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221901

  • CVE-2022-20432HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221899

  • CVE-2022-20431HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221238

  • CVE-2022-20430HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221233

  • CVE-2022-39119HigSep 9, 2022
    risk 0.51cvss 7.8epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed