VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,183)

page 101 of 210
  • CVE-2011-3617MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

  • CVE-2019-5879MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

  • CVE-2015-1780MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.01

    oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

  • CVE-2012-2238HigNov 21, 2019
    risk 0.42cvss 7.5epss 0.02

    trytond 2.4: ModelView.button fails to validate authorization

  • CVE-2019-6144MedOct 23, 2019
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.

  • CVE-2019-14832HigOct 15, 2019
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.

  • CVE-2019-16884HigSep 25, 2019
    risk 0.42cvss 7.5epss 0.04

    runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

  • CVE-2019-6838MedSep 17, 2019
    risk 0.42cvss 6.5epss 0.01

    A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a…

  • CVE-2019-9149MedJul 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the private key password is cached. A second…

  • CVE-2019-12492MedJun 6, 2019
    risk 0.42cvss 6.5epss 0.01

    Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services.

  • CVE-2019-10014MedMar 24, 2019
    risk 0.42cvss 6.5epss 0.01

    In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.

  • CVE-2018-1000420MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.

  • CVE-2018-17195HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.01

    The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication,…

  • CVE-2018-15693MedNov 16, 2018
    risk 0.42cvss 6.4epss 0.01

    Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference.

  • CVE-2018-15692MedNov 16, 2018
    risk 0.42cvss 6.4epss 0.01

    Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions.

  • CVE-2018-15405MedOct 5, 2018
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to an authorization check that…

  • CVE-2018-0460MedOct 5, 2018
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks. An attacker could…

  • CVE-2018-0459MedOct 5, 2018
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server-side authorization…

  • CVE-2018-1250MedSep 28, 2018
    risk 0.42cvss 6.5epss 0.02

    Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing…

  • CVE-2018-1999047MedAug 23, 2018
    risk 0.42cvss 6.5epss 0.01

    A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.