VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 146 of 187
  • CVE-2021-20229MedFeb 23, 2021
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

  • CVE-2021-22113MedFeb 23, 2021
    risk 0.28cvss 5.3epss 0.01

    Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring…

  • CVE-2021-25774MedFeb 3, 2021
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.

  • CVE-2021-1143MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. An attacker could…

  • CVE-2021-21609MedJan 13, 2021
    risk 0.28cvss 5.3epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.

  • CVE-2020-25701MedNov 19, 2020
    risk 0.28cvss 5.3epss 0.01

    If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to…

  • CVE-2020-26506MedNov 5, 2020
    risk 0.28cvss 4.3epss 0.01

    An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative users. The accessed files were not visible by the low privileged users in the web GUI.

  • CVE-2020-13335MedOct 7, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

  • CVE-2020-3474MedSep 24, 2020
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, resulting in a…

  • CVE-2020-13313MedSep 14, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.

  • CVE-2020-5418MedSep 3, 2020
    risk 0.28cvss 4.3epss 0.01

    Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).

  • CVE-2020-25025MedSep 2, 2020
    risk 0.28cvss 4.3epss 0.01

    The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).

  • CVE-2020-3413MedAug 17, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient authorization…

  • CVE-2020-3412MedAug 17, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization…

  • CVE-2020-4026MedJun 3, 2020
    risk 0.28cvss 4.3epss 0.01

    The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including…

  • CVE-2020-4446MedMay 6, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.

  • CVE-2020-2188MedMay 6, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2020-5333MedMay 4, 2020
    risk 0.28cvss 4.3epss 0.01

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.

  • CVE-2019-13001MedMar 10, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass.

  • CVE-2019-4745MedFeb 24, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.