VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 96 of 464
  • CVE-2019-13408HigAug 29, 2019
    risk 0.49cvss 7.5epss 0.02

    A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.

  • CVE-2019-15136HigAug 18, 2019
    risk 0.49cvss 7.5epss 0.01

    The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.

  • CVE-2019-14475HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.02

    eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a…

  • CVE-2019-1010066HigJul 18, 2019
    risk 0.49cvss 7.5epss 0.01

    Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: An attacker could exploit a bug in ioctl interface whitelist…

  • CVE-2019-11611HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.03

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

  • CVE-2019-11610HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.03

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

  • CVE-2019-11607HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.03

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

  • CVE-2019-11606HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.03

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

  • CVE-2019-3399HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.02

    The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.

  • CVE-2019-9742HigMar 13, 2019
    risk 0.49cvss 7.5epss 0.01

    gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not properly protected, leading to unintended…

  • CVE-2019-9713HigMar 12, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.

  • CVE-2019-9574HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.02

    The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role.

  • CVE-2018-19079HigNov 7, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot.

  • CVE-2018-18377HigOct 16, 2018
    risk 0.49cvss 7.5epss 0.01

    goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.

  • CVE-2018-7792HigAug 29, 2018
    risk 0.49cvss 7.5epss 0.01

    A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

  • CVE-2018-5135HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.01

    WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox <…

  • CVE-2018-5113HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

  • CVE-2018-8012HigMay 21, 2018
    risk 0.49cvss 7.5epss 0.08

    No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

  • CVE-2017-10846HigSep 15, 2017
    risk 0.49cvss 7.5epss 0.01

    Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors.

  • CVE-2017-1002151HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.01

    Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization