VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,735)

page 14 of 187
  • CVE-2023-52538CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-25170CriFeb 28, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

  • CVE-2017-9453CriSep 5, 2023
    risk 0.59cvss 9.0epss 0.01

    BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

  • CVE-2023-33468CriAug 9, 2023
    risk 0.59cvss 9.1epss 0.01

    KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly…

  • CVE-2023-31997CriJul 1, 2023
    risk 0.59cvss 9.0epss 0.00

    UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the…

  • CVE-2023-34218CriMay 31, 2023
    risk 0.59cvss 9.1epss 0.01

    In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible

  • CVE-2023-23304CriMay 23, 2023
    risk 0.59cvss 9.1epss 0.01

    The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module…

  • CVE-2023-27578CriMar 20, 2023
    risk 0.59cvss 9.1epss 0.01

    Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages…

  • CVE-2023-22610CriJan 31, 2023
    risk 0.59cvss 9.1epss 0.01

    A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.

  • CVE-2023-22482CriJan 26, 2023
    risk 0.59cvss 9.0epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers…

  • CVE-2022-45891CriDec 25, 2022
    risk 0.59cvss 9.1epss 0.01

    Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).

  • CVE-2022-41923CriNov 23, 2022
    risk 0.59cvss 9.1epss 0.02

    Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework…

  • CVE-2022-31247CriSep 7, 2022
    risk 0.59cvss 9.1epss 0.01

    An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner…

  • CVE-2022-0670CriJul 25, 2022
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise…

  • CVE-2022-26629CriMar 24, 2022
    risk 0.59cvss 9.1epss 0.03

    An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

  • CVE-2022-0482CriMar 9, 2022
    risk 0.59cvss 9.1epss 0.44

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

  • CVE-2021-39233CriNov 19, 2021
    risk 0.59cvss 9.1epss 0.02

    In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

  • CVE-2021-41244CriNov 15, 2021
    risk 0.59cvss 9.1epss 0.03

    Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.…

  • CVE-2021-30925CriAug 24, 2021
    risk 0.59cvss 9.1epss 0.01

    The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.

  • CVE-2021-30856CriAug 24, 2021
    risk 0.59cvss 9.1epss 0.01

    This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences.