VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 139 of 187
  • CVE-2024-12148MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

  • CVE-2023-52944MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.

  • CVE-2023-52943MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting function via unspecified vectors.

  • CVE-2024-45204MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial…

  • CVE-2024-50671MedNov 25, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character…

  • CVE-2024-11672MedNov 25, 2024
    risk 0.28cvss 4.3epss 0.01

    Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

  • CVE-2024-48901MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.

  • CVE-2024-48897MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.

  • CVE-2024-10953MedNov 9, 2024
    risk 0.28cvss 4.3epss 0.00

    An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of.

  • CVE-2024-21249MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft…

  • CVE-2024-45125MedOct 10, 2024
    risk 0.28cvss 4.3epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to have a low impact on integrity.…

  • CVE-2024-47804MedOct 2, 2024
    risk 0.28cvss 4.3epss 0.01

    If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates…

  • CVE-2024-9155MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.

  • CVE-2024-47060MedSep 20, 2024
    risk 0.28cvss 4.3epss 0.00

    Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other organizations can still log in and access through these applications, leading to…

  • CVE-2024-47160MedSep 19, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

  • CVE-2024-47159MedSep 19, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

  • CVE-2024-7836MedAug 22, 2024
    risk 0.28cvss 4.3epss 0.00

    The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, with Contributor-level access and…

  • CVE-2024-7711MedAug 20, 2024
    risk 0.28cvss 4.3epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub…

  • CVE-2024-41941MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify settings in the application without authorization.

  • CVE-2024-7266MedAug 7, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16…