VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 118 of 187
  • CVE-2020-4794MedDec 21, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization…

  • CVE-2020-28053MedNov 23, 2020
    risk 0.35cvss 6.5epss 0.01

    HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.

  • CVE-2020-8278MedNov 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.

  • CVE-2020-3852MedOct 27, 2020
    risk 0.35cvss 5.3epss 0.01

    A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining multimedia permission for a website.

  • CVE-2020-3578MedOct 21, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and access parts of the WebVPN portal that are…

  • CVE-2020-27609MedOct 21, 2020
    risk 0.35cvss 5.3epss 0.01

    BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.

  • CVE-2020-16904MedOct 16, 2020
    risk 0.35cvss 5.3epss 0.03

    An elevation of privilege vulnerability exists in the way Azure Functions validate access keys. An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization. This security update addresses…

  • CVE-2020-15126MedJul 22, 2020
    risk 0.35cvss 6.5epss 0.01

    In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.

  • CVE-2020-15513MedJul 7, 2020
    risk 0.35cvss 5.3epss 0.01

    The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.

  • CVE-2020-14196MedJul 1, 2020
    risk 0.35cvss 5.3epss 0.02

    In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.

  • CVE-2020-3364MedJun 18, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the standby route processor management Gigabit…

  • CVE-2020-3360MedJun 18, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management…

  • CVE-2019-20801MedMay 18, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a…

  • CVE-2020-1998MedMay 13, 2020
    risk 0.35cvss 5.4epss 0.01

    An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and…

  • CVE-2020-11628MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client.…

  • CVE-2020-7955MedJan 31, 2020
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

  • CVE-2018-20492MedDec 26, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

  • CVE-2018-18819MedNov 12, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1…

  • CVE-2019-4311MedOct 29, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 161037.

  • CVE-2016-10996MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.01

    The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak.