VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 114 of 187
  • CVE-2023-47090MedOct 30, 2023
    risk 0.35cvss 6.5epss 0.01

    NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest…

  • CVE-2023-46125MedOct 25, 2023
    risk 0.35cvss 6.5epss 0.01

    Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows users to retrieve its configuration using the `GET…

  • CVE-2023-22067MedOct 17, 2023
    risk 0.35cvss 5.3epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable…

  • CVE-2022-48538MedAug 22, 2023
    risk 0.35cvss 5.3epss 0.01

    In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.

  • CVE-2023-35908MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected

  • CVE-2023-3574MedJul 10, 2023
    risk 0.35cvss 6.5epss 0.01

    Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.

  • CVE-2023-34197MedJul 7, 2023
    risk 0.35cvss 5.4epss 0.04

    Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make…

  • CVE-2023-37300MedJun 30, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.

  • CVE-2023-32061MedJun 13, 2023
    risk 0.35cvss 5.4epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide…

  • CVE-2023-34965MedJun 13, 2023
    risk 0.35cvss 5.3epss 0.01

    SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.

  • CVE-2021-4352MedJun 7, 2023
    risk 0.35cvss 5.3epss 0.01

    The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the…

  • CVE-2020-36710MedJun 7, 2023
    risk 0.35cvss 5.3epss 0.01

    The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.

  • CVE-2023-29240MedMay 3, 2023
    risk 0.35cvss 5.4epss 0.00

    An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2022-25091MedApr 27, 2023
    risk 0.35cvss 5.3epss 0.01

    Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature.

  • CVE-2022-25274MedApr 26, 2023
    risk 0.35cvss 5.4epss 0.00

    Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have…

  • CVE-2022-43770MedApr 11, 2023
    risk 0.35cvss 5.4epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.   

  • CVE-2023-25924MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.

  • CVE-2023-25768MedFeb 15, 2023
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.

  • CVE-2023-0298MedJan 14, 2023
    risk 0.35cvss 6.5epss 0.01

    Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.

  • CVE-2022-45956MedDec 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.