CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 116 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41013 | Med | 0.35 | 5.3 | 0.01 | Dec 8, 2021 | An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs. | ||
| CVE-2021-43781 | Med | 0.35 | 6.4 | 0.01 | Dec 6, 2021 | Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable… | ||
| CVE-2021-3992 | Med | 0.35 | 6.5 | 0.01 | Dec 1, 2021 | kimai2 is vulnerable to Improper Access Control | ||
| CVE-2021-24842 | Med | 0.35 | 5.4 | 0.01 | Nov 29, 2021 | The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts. | ||
| CVE-2021-43560 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2021 | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events. | ||
| CVE-2021-25973 | Med | 0.35 | 6.5 | 0.01 | Nov 2, 2021 | In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only. | ||
| CVE-2021-24757 | Med | 0.35 | 5.3 | 0.01 | Nov 1, 2021 | The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images. | ||
| CVE-2021-20803 | Med | 0.35 | 5.4 | 0.01 | Oct 13, 2021 | Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen. | ||
| CVE-2021-40456 | Med | 0.35 | 5.3 | 0.02 | Oct 13, 2021 | Windows AD FS Security Feature Bypass Vulnerability | ||
| CVE-2021-42137 | Med | 0.35 | 5.3 | 0.01 | Oct 11, 2021 | An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc. | ||
| CVE-2021-22262 | Med | 0.35 | 5.4 | 0.01 | Oct 5, 2021 | Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and… | ||
| CVE-2019-16651 | Med | 0.35 | 5.3 | 0.01 | Sep 20, 2021 | An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN… | ||
| CVE-2021-28567 | Med | 0.35 | 6.5 | 0.01 | Sep 8, 2021 | Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin… | ||
| CVE-2021-35949 | Med | 0.35 | 5.3 | 0.01 | Sep 7, 2021 | The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share. | ||
| CVE-2021-39119 | Med | 0.35 | 5.3 | 0.01 | Sep 1, 2021 | Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected… | ||
| CVE-2021-34434 | Med | 0.35 | 5.3 | 0.01 | Aug 30, 2021 | In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked. | ||
| CVE-2021-22256 | Med | 0.35 | 5.4 | 0.01 | Aug 25, 2021 | Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status | ||
| CVE-2021-37598 | Med | 0.35 | 5.3 | 0.02 | Aug 19, 2021 | WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character. | ||
| CVE-2021-27793 | Med | 0.35 | 5.3 | 0.01 | Aug 12, 2021 | ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the… | ||
| CVE-2020-28397 | Med | 0.35 | 5.3 | 0.01 | Aug 10, 2021 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl.… |
- risk 0.35cvss 5.3epss 0.01
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
- risk 0.35cvss 6.4epss 0.01
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable…
- risk 0.35cvss 6.5epss 0.01
kimai2 is vulnerable to Improper Access Control
- risk 0.35cvss 5.4epss 0.01
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.
- risk 0.35cvss 5.3epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
- risk 0.35cvss 6.5epss 0.01
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.
- risk 0.35cvss 5.3epss 0.01
The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.
- risk 0.35cvss 5.4epss 0.01
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.
- risk 0.35cvss 5.3epss 0.02
Windows AD FS Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of tickets that shows title, state, etc.
- risk 0.35cvss 5.4epss 0.01
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and…
- risk 0.35cvss 5.3epss 0.01
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN…
- risk 0.35cvss 6.5epss 0.01
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin…
- risk 0.35cvss 5.3epss 0.01
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
- risk 0.35cvss 5.3epss 0.01
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected…
- risk 0.35cvss 5.3epss 0.01
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
- risk 0.35cvss 5.4epss 0.01
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
- risk 0.35cvss 5.3epss 0.02
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
- risk 0.35cvss 5.3epss 0.01
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the…
- risk 0.35cvss 5.3epss 0.01
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl.…