VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 164 of 213
  • CVE-2025-21562MedJan 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2025-21517MedJan 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2025-24460MedJan 21, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool

  • CVE-2024-57683MedJan 16, 2025
    risk 0.28cvss 4.3epss 0.01

    An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.

  • CVE-2024-13271MedJan 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.

  • CVE-2024-13270MedJan 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.

  • CVE-2024-56350MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects

  • CVE-2024-56348MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents

  • CVE-2024-12148MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

  • CVE-2023-52944MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.

  • CVE-2023-52943MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on the alerting function via unspecified vectors.

  • CVE-2024-45204MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial…

  • CVE-2024-50671MedNov 25, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character…

  • CVE-2024-11672MedNov 25, 2024
    risk 0.28cvss 4.3epss 0.01

    Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

  • CVE-2024-48901MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.

  • CVE-2024-48897MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.

  • CVE-2024-10953MedNov 9, 2024
    risk 0.28cvss 4.3epss 0.00

    An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of.

  • CVE-2024-21249MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft…

  • CVE-2024-45125MedOct 10, 2024
    risk 0.28cvss 4.3epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to have a low impact on integrity.…

  • CVE-2024-47804MedOct 2, 2024
    risk 0.28cvss 4.3epss 0.01

    If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates…