VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 147 of 187
  • CVE-2013-4228MedFeb 18, 2020
    risk 0.28cvss 4.3epss 0.01

    The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary…

  • CVE-2020-8119MedFeb 4, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.

  • CVE-2020-6307MedJan 14, 2020
    risk 0.28cvss 4.3epss 0.01

    Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.

  • CVE-2012-3821MedJan 10, 2020
    risk 0.28cvss 4.3epss 0.01

    A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.

  • CVE-2019-12837MedDec 31, 2019
    risk 0.28cvss 4.3epss 0.01

    The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.

  • CVE-2018-20498MedDec 30, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

  • CVE-2018-20493MedDec 30, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

  • CVE-2019-11294MedDec 19, 2019
    risk 0.28cvss 4.3epss 0.01

    Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.

  • CVE-2013-4411MedDec 3, 2019
    risk 0.28cvss 4.3epss 0.01

    Review Board: URL processing gives unauthorized users access to review lists

  • CVE-2019-5864MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.00

    Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

  • CVE-2019-13716MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2019-4509MedNov 9, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to incorrect authorization in some components which could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 164430.

  • CVE-2018-21030MedOct 31, 2019
    risk 0.28cvss 5.3epss 0.01

    Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

  • CVE-2019-1192MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An…

  • CVE-2018-20826MedAug 9, 2019
    risk 0.28cvss 4.3epss 0.01

    The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.

  • CVE-2019-5838MedJun 27, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.

  • CVE-2019-0762MedApr 9, 2019
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.

  • CVE-2019-3848MedMar 26, 2019
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was…

  • CVE-2018-7366MedDec 28, 2018
    risk 0.28cvss 4.3epss 0.01

    ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform…

  • CVE-2018-7363MedNov 16, 2018
    risk 0.28cvss 4.3epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account credentials.