VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 138 of 213
  • CVE-2018-20492MedDec 26, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

  • CVE-2018-18819MedNov 12, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1…

  • CVE-2019-4311MedOct 29, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 161037.

  • CVE-2016-10996MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.01

    The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak.

  • CVE-2019-14995MedSep 11, 2019
    risk 0.35cvss 5.3epss 0.03

    The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

  • CVE-2019-8445MedAug 23, 2019
    risk 0.35cvss 5.3epss 0.03

    Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.

  • CVE-2019-13417MedAug 12, 2019
    risk 0.35cvss 5.3epss 0.01

    Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

  • CVE-2019-3401MedMay 22, 2019
    risk 0.35cvss 5.3epss 0.13

    The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

  • CVE-2018-20685MedJan 10, 2019
    risk 0.35cvss 5.3epss 0.04

    In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

  • CVE-2018-20147MedDec 14, 2018
    risk 0.35cvss 6.5epss 0.03

    In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.

  • CVE-2018-8927MedJun 14, 2018
    risk 0.35cvss 5.4epss 0.01

    Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter.

  • CVE-2018-10212MedApr 25, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value.

  • CVE-2018-1000107MedMar 13, 2018
    risk 0.35cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure permission and without…

  • CVE-2017-18095MedFeb 19, 2018
    risk 0.35cvss 5.3epss 0.01

    The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.

  • CVE-2017-12197MedJan 18, 2018
    risk 0.35cvss 6.5epss 0.02

    It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.

  • CVE-2007-3968MedJul 25, 2007
    risk 0.35cvss 5.3epss 0.01

    index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name.

  • CVE-2026-102806MedSep 29, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session…

  • CVE-2026-100556MedSep 26, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the…

  • CVE-2026-63342MedSep 21, 2026
    risk 0.34cvss 6.3epss 0.00

    Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-task} endpoint implemented by…

  • CVE-2026-11540MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.