VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 25 of 187
  • CVE-2020-25239HigMar 15, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker…

  • CVE-2021-21481HigMar 9, 2021
    risk 0.57cvss 8.8epss 0.01

    The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This…

  • CVE-2021-1305HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information…

  • CVE-2021-1144HigJan 13, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization checks for changing…

  • CVE-2020-24674HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.03

    In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.

  • CVE-2020-2286HigOct 8, 2020
    risk 0.57cvss 8.8epss 0.01

    Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration.

  • CVE-2019-19200HigOct 6, 2020
    risk 0.57cvss 8.8epss 0.02

    REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.

  • CVE-2020-4621HigSep 22, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization checks. IBM X-Force ID: 184981.

  • CVE-2020-3386HigJul 31, 2020
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient authorization of…

  • CVE-2020-2228HigJul 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.

  • CVE-2020-11753HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default…

  • CVE-2020-0981HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.01

    A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level, leading to…

  • CVE-2020-11707HigApr 12, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full control of, breaking out of the sandbox.

  • CVE-2019-11361HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.03

    Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.

  • CVE-2020-10239HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

  • CVE-2020-5239HigFeb 13, 2020
    risk 0.57cvss 8.7epss 0.01

    In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrusted users are most impacted. The master and 1.7 branches are patched on our git…

  • CVE-2020-6380HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.

  • CVE-2019-14843HigJan 7, 2020
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped…

  • CVE-2010-3782HigJan 2, 2020
    risk 0.57cvss 8.8epss 0.01

    obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.

  • CVE-2019-0384HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user…