VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 93 of 464
  • CVE-2022-38370HigSep 5, 2022
    risk 0.49cvss 7.5epss 0.01

    Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.

  • CVE-2022-2379HigAug 15, 2022
    risk 0.49cvss 7.5epss 0.03

    The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone…

  • CVE-2021-33057HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use…

  • CVE-2022-33913HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

  • CVE-2022-32560HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

  • CVE-2022-30746HigJun 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

  • CVE-2022-26650HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters…

  • CVE-2021-25002HigMay 2, 2022
    risk 0.49cvss 7.5epss 0.01

    The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL

  • CVE-2022-27669HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.

  • CVE-2022-27480HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.

  • CVE-2022-27658HigMar 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.

  • CVE-2021-3814HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.01

    It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

  • CVE-2021-25087HigMar 7, 2022
    risk 0.49cvss 7.5epss 0.02

    The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and…

  • CVE-2022-24317HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

  • CVE-2021-24839HigFeb 7, 2022
    risk 0.49cvss 7.5epss 0.01

    The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions…

  • CVE-2021-25093HigFeb 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

  • CVE-2021-24906HigJan 24, 2022
    risk 0.49cvss 7.5epss 0.01

    The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

  • CVE-2021-38789HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which a third-party app could change system settings.

  • CVE-2022-0236HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.04

    The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file.…

  • CVE-2021-24831HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.