VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 173 of 213
  • CVE-2019-11294MedDec 19, 2019
    risk 0.28cvss 4.3epss 0.01

    Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.

  • CVE-2019-5864MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.00

    Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

  • CVE-2019-13716MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2019-4509MedNov 9, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to incorrect authorization in some components which could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 164430.

  • CVE-2018-21030MedOct 31, 2019
    risk 0.28cvss 5.3epss 0.01

    Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

  • CVE-2019-1192MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An…

  • CVE-2018-20826MedAug 9, 2019
    risk 0.28cvss 4.3epss 0.01

    The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.

  • CVE-2019-5838MedJun 27, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.

  • CVE-2019-0762MedApr 9, 2019
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.

  • CVE-2019-3848MedMar 26, 2019
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was…

  • CVE-2018-7366MedDec 28, 2018
    risk 0.28cvss 4.3epss 0.01

    ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform…

  • CVE-2018-7363MedNov 16, 2018
    risk 0.28cvss 4.3epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account credentials.

  • CVE-2018-17857MedOct 9, 2018
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access level violation.

  • CVE-2018-3778MedAug 8, 2018
    risk 0.28cvss 5.3epss 0.01

    Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.

  • CVE-2017-17708MedJul 31, 2018
    risk 0.28cvss 4.3epss 0.01

    Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.

  • CVE-2018-0269MedApr 19, 2018
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cross Origin Resource…

  • CVE-2017-2599MedApr 11, 2018
    risk 0.28cvss 5.4epss 0.01

    Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).

  • CVE-2017-1766MedMar 30, 2018
    risk 0.28cvss 4.3epss 0.01

    Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.

  • CVE-2017-0920MedMar 22, 2018
    risk 0.28cvss 4.3epss 0.01

    GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab…

  • CVE-2018-1000114MedMar 13, 2018
    risk 0.28cvss 4.3epss 0.01

    An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.