VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 126 of 187
  • CVE-2024-24773MedFeb 28, 2024
    risk 0.32cvss 4.9epss 0.01

    Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which fixes the issue.

  • CVE-2023-46906MedJan 9, 2024
    risk 0.32cvss 4.9epss 0.01

    juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly validated.

  • CVE-2023-51379MedDec 21, 2023
    risk 0.32cvss 4.9epss 0.01

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with an improperly scoped token. This vulnerability did not allow unauthorized access to any repository content as it also required contents:write and…

  • CVE-2023-5193MedSep 29, 2023
    risk 0.32cvss 4.9epss 0.00

    Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

  • CVE-2023-37881MedSep 12, 2023
    risk 0.32cvss 4.9epss 0.00

    Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

  • CVE-2023-3814MedSep 4, 2023
    risk 0.32cvss 4.9epss 0.01

    The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.

  • CVE-2023-37492MedAug 8, 2023
    risk 0.32cvss 4.9epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 793,…

  • CVE-2023-32482MedJul 20, 2023
    risk 0.32cvss 4.9epss 0.00

    Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious user with privileged access can push policies to unauthorized tenant group.

  • CVE-2020-25167MedApr 18, 2022
    risk 0.32cvss 4.9epss 0.01

    OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.

  • CVE-2021-40504MedNov 10, 2021
    risk 0.32cvss 4.9epss 0.01

    A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, contains transport authorizations, which exceed expected display only permissions.

  • CVE-2021-22535MedSep 28, 2021
    risk 0.32cvss 4.9epss 0.01

    Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.

  • CVE-2021-22253MedAug 23, 2021
    risk 0.32cvss 4.9epss 0.01

    Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

  • CVE-2021-29158MedApr 23, 2021
    risk 0.32cvss 4.9epss 0.01

    Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.

  • CVE-2021-22186MedMar 24, 2021
    risk 0.32cvss 4.9epss 0.01

    An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners

  • CVE-2020-26028MedDec 28, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.

  • CVE-2017-2632MedJul 27, 2018
    risk 0.32cvss 4.9epss 0.01

    A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate…

  • CVE-2026-73213MedAug 11, 2026
    risk 0.31cvss epss 0.00

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an…

  • CVE-2026-35622MedApr 9, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authentication by providing non-deployment add-on…

  • CVE-2026-33424MedMar 21, 2026
    risk 0.31cvss 5.9epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacker can grant access to a private message topic through invites even after they lose access to that PM. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2…

  • CVE-2026-32039MedMar 19, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can exploit untyped sender keys by forcing…