VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 172 of 213
  • CVE-2020-13335MedOct 7, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

  • CVE-2020-3474MedSep 24, 2020
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, resulting in a…

  • CVE-2020-13313MedSep 14, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.

  • CVE-2020-5418MedSep 3, 2020
    risk 0.28cvss 4.3epss 0.01

    Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).

  • CVE-2020-25025MedSep 2, 2020
    risk 0.28cvss 4.3epss 0.01

    The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).

  • CVE-2020-3413MedAug 17, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient authorization…

  • CVE-2020-3412MedAug 17, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization…

  • CVE-2020-4026MedJun 3, 2020
    risk 0.28cvss 4.3epss 0.01

    The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including…

  • CVE-2020-4446MedMay 6, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote attacker to bypass security restrictions, caused by the failure to perform insufficient authorization checks. IBM X-Force ID: 181126.

  • CVE-2020-2188MedMay 6, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2020-5333MedMay 4, 2020
    risk 0.28cvss 4.3epss 0.01

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.

  • CVE-2019-13001MedMar 10, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows authentication bypass.

  • CVE-2019-4745MedFeb 24, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.

  • CVE-2013-4228MedFeb 18, 2020
    risk 0.28cvss 4.3epss 0.01

    The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary…

  • CVE-2020-8119MedFeb 4, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.

  • CVE-2020-6307MedJan 14, 2020
    risk 0.28cvss 4.3epss 0.01

    Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.

  • CVE-2012-3821MedJan 10, 2020
    risk 0.28cvss 4.3epss 0.01

    A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.

  • CVE-2019-12837MedDec 31, 2019
    risk 0.28cvss 4.3epss 0.01

    The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.

  • CVE-2018-20498MedDec 30, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

  • CVE-2018-20493MedDec 30, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.