CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 93 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38370 | Hig | 0.49 | 7.5 | 0.01 | Sep 5, 2022 | Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. | ||
| CVE-2022-2379 | Hig | 0.49 | 7.5 | 0.03 | Aug 15, 2022 | The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone… | ||
| CVE-2021-33057 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use… | ||
| CVE-2022-33913 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2022 | In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check. | ||
| CVE-2022-32560 | Hig | 0.49 | 7.5 | 0.01 | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. | ||
| CVE-2022-30746 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2022 | Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API. | ||
| CVE-2022-26650 | Hig | 0.49 | 7.5 | 0.03 | May 17, 2022 | In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters… | ||
| CVE-2021-25002 | Hig | 0.49 | 7.5 | 0.01 | May 2, 2022 | The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL | ||
| CVE-2022-27669 | Hig | 0.49 | 7.5 | 0.01 | Apr 12, 2022 | An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges. | ||
| CVE-2022-27480 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files. | ||
| CVE-2022-27658 | Hig | 0.49 | 7.5 | 0.01 | Mar 28, 2022 | Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks. | ||
| CVE-2021-3814 | Hig | 0.49 | 7.5 | 0.01 | Mar 25, 2022 | It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure. | ||
| CVE-2021-25087 | Hig | 0.49 | 7.5 | 0.02 | Mar 7, 2022 | The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and… | ||
| CVE-2022-24317 | Hig | 0.49 | 7.5 | 0.01 | Feb 9, 2022 | A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | ||
| CVE-2021-24839 | Hig | 0.49 | 7.5 | 0.01 | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions… | ||
| CVE-2021-25093 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2022 | The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request | ||
| CVE-2021-24906 | Hig | 0.49 | 7.5 | 0.01 | Jan 24, 2022 | The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request | ||
| CVE-2021-38789 | Hig | 0.49 | 7.5 | 0.01 | Jan 19, 2022 | Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which a third-party app could change system settings. | ||
| CVE-2022-0236 | Hig | 0.49 | 7.5 | 0.04 | Jan 18, 2022 | The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file.… | ||
| CVE-2021-24831 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs. |
- risk 0.49cvss 7.5epss 0.01
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
- risk 0.49cvss 7.5epss 0.03
The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone…
- risk 0.49cvss 7.5epss 0.01
The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use…
- risk 0.49cvss 7.5epss 0.01
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
- risk 0.49cvss 7.5epss 0.01
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.
- risk 0.49cvss 7.5epss 0.03
In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters…
- risk 0.49cvss 7.5epss 0.01
The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL
- risk 0.49cvss 7.5epss 0.01
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
- risk 0.49cvss 7.5epss 0.02
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.
- risk 0.49cvss 7.5epss 0.01
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
- risk 0.49cvss 7.5epss 0.01
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
- risk 0.49cvss 7.5epss 0.02
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and…
- risk 0.49cvss 7.5epss 0.01
A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
- risk 0.49cvss 7.5epss 0.01
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions…
- risk 0.49cvss 7.5epss 0.01
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request
- risk 0.49cvss 7.5epss 0.01
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request
- risk 0.49cvss 7.5epss 0.01
Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which a third-party app could change system settings.
- risk 0.49cvss 7.5epss 0.04
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file.…
- risk 0.49cvss 7.5epss 0.01
All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.