VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 23 of 187
  • CVE-2022-36634HigOct 7, 2022
    risk 0.57cvss 8.8epss 0.01

    An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.

  • CVE-2022-1245CriJul 8, 2022
    risk 0.57cvss 9.8epss 0.01

    A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain…

  • CVE-2022-22967HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell…

  • CVE-2022-30016HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.

  • CVE-2022-23139HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.01

    ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that…

  • CVE-2022-0981HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.

  • CVE-2021-44550CriFeb 24, 2022
    risk 0.57cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).

  • CVE-2020-25722HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.

  • CVE-2022-24450HigFeb 8, 2022
    risk 0.57cvss 8.8epss 0.01

    NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.

  • CVE-2021-4133HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

  • CVE-2021-38017HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-38016HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • CVE-2021-23803CriDec 17, 2021
    risk 0.57cvss 9.8epss 0.02

    This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will…

  • CVE-2021-45102HigDec 16, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.

  • CVE-2021-29678HigDec 9, 2021
    risk 0.57cvss 8.7epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.

  • CVE-2021-42758HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.02

    An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.

  • CVE-2021-24917HigDec 6, 2021
    risk 0.57cvss 7.5epss 0.72

    The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

  • CVE-2021-22966HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.01

    Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a…

  • CVE-2021-39232HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.02

    In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

  • CVE-2021-21693CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.