CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 95 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20885 | Hig | 0.49 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file. | ||
| CVE-2020-13270 | Hig | 0.49 | 7.5 | 0.01 | Jun 10, 2020 | Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API | ||
| CVE-2020-12745 | Hig | 0.49 | 7.5 | 0.00 | May 11, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipboard content via USSD. The Samsung ID is SVE-2019-16556 (May 2020). | ||
| CVE-2018-21047 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant because Internet access begins before the Setup Wizard finishes. The Samsung ID is SVE-2018-12894 (November 2018). | ||
| CVE-2017-18677 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Because of an unprotected Intent, an attacker can reset the configuration of certain applications. The Samsung ID is SVE-2016-7142 (April 2017). | ||
| CVE-2017-18666 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Applications can send arbitrary premium SMS messages. The Samsung ID is SVE-2017-8701 (June 2017). | ||
| CVE-2020-11463 | Hig | 0.49 | 7.5 | 0.02 | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This… | ||
| CVE-2019-20614 | Hig | 0.49 | 7.5 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Allshare allows attackers to access sensitive information. The Samsung ID is SVE-2018-13453 (March 2019). | ||
| CVE-2019-20599 | Hig | 0.49 | 7.5 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Voice Assistant mishandles the notification audibility of a secured app. The Samsung ID is SVE-2018-13326 (May 2019). | ||
| CVE-2018-13063 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2020 | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. | ||
| CVE-2020-6209 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2020 | SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Check. | ||
| CVE-2019-19989 | Hig | 0.49 | 7.5 | 0.01 | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization. | ||
| CVE-2020-7968 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | ||
| CVE-2020-5228 | Hig | 0.49 | 7.6 | 0.01 | Jan 30, 2020 | Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This leads to users unknowingly… | ||
| CVE-2019-5470 | Hig | 0.49 | 7.5 | 0.02 | Jan 28, 2020 | An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information. | ||
| CVE-2018-19830 | Hig | 0.49 | 7.5 | 0.01 | Dec 31, 2019 | The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's… | ||
| CVE-2019-15576 | Hig | 0.49 | 7.5 | 0.02 | Dec 18, 2019 | An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint. | ||
| CVE-2019-16906 | Hig | 0.49 | 7.5 | 0.02 | Oct 31, 2019 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These… | ||
| CVE-2019-18383 | Hig | 0.49 | 7.5 | 0.02 | Oct 23, 2019 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin without permission. | ||
| CVE-2019-12944 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2019 | Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is unavailable. |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
- risk 0.49cvss 7.5epss 0.01
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipboard content via USSD. The Samsung ID is SVE-2019-16556 (May 2020).
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant because Internet access begins before the Setup Wizard finishes. The Samsung ID is SVE-2018-12894 (November 2018).
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Because of an unprotected Intent, an attacker can reset the configuration of certain applications. The Samsung ID is SVE-2016-7142 (April 2017).
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Applications can send arbitrary premium SMS messages. The Samsung ID is SVE-2017-8701 (June 2017).
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Allshare allows attackers to access sensitive information. The Samsung ID is SVE-2018-13453 (March 2019).
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Voice Assistant mishandles the notification audibility of a secured app. The Samsung ID is SVE-2018-13326 (May 2019).
- risk 0.49cvss 7.5epss 0.01
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
- risk 0.49cvss 7.5epss 0.01
SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Check.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization.
- risk 0.49cvss 7.5epss 0.01
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
- risk 0.49cvss 7.6epss 0.01
Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This leads to users unknowingly…
- risk 0.49cvss 7.5epss 0.02
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
- risk 0.49cvss 7.5epss 0.01
The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's…
- risk 0.49cvss 7.5epss 0.02
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin without permission.
- risk 0.49cvss 7.5epss 0.01
Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is unavailable.