VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 24 of 187
  • CVE-2021-21692CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access permission on the source path, instead of 'delete'.

  • CVE-2021-21691CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-24717HigNov 1, 2021
    risk 0.57cvss 8.8epss 0.01

    The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

  • CVE-2021-39321HigOct 21, 2021
    risk 0.57cvss 8.8epss 0.02

    Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the…

  • CVE-2021-38299CriSep 27, 2021
    risk 0.57cvss 9.8epss 0.02

    Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.

  • CVE-2020-19551HigSep 21, 2021
    risk 0.57cvss 8.8epss 0.02

    Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.

  • CVE-2020-25564HigAug 11, 2021
    risk 0.57cvss 8.8epss 0.01

    In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature.

  • CVE-2021-36230HigJul 20, 2021
    risk 0.57cvss 8.8epss 0.01

    HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.

  • CVE-2021-36132HigJul 2, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform…

  • CVE-2020-27362HigJul 1, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges.

  • CVE-2021-27661HigJul 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically…

  • CVE-2020-20471HigJun 21, 2021
    risk 0.57cvss 8.8epss 0.02

    White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.

  • CVE-2020-26559HigMay 24, 2021
    risk 0.57cvss 8.8epss 0.01

    Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning…

  • CVE-2021-28826HigApr 14, 2021
    risk 0.57cvss 8.8epss 0.00

    The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnerability that theoretically allows a low…

  • CVE-2021-28825HigApr 14, 2021
    risk 0.57cvss 8.8epss 0.00

    The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low…

  • CVE-2021-28824HigMar 23, 2021
    risk 0.57cvss 8.8epss 0.00

    The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access…

  • CVE-2021-28823HigMar 23, 2021
    risk 0.57cvss 8.8epss 0.00

    The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the…

  • CVE-2021-28821HigMar 23, 2021
    risk 0.57cvss 8.8epss 0.00

    The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability that theoretically allows a low privileged…

  • CVE-2021-28819HigMar 23, 2021
    risk 0.57cvss 8.8epss 0.00

    The Windows Installation component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the…

  • CVE-2020-25240HigMar 15, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain information from logs and templates of the service.