VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 53 of 187
  • CVE-2024-27138HigMar 1, 2024
    risk 0.49cvss 7.5epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache…

  • CVE-2023-52374HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52361HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.

  • CVE-2023-47142HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.

  • CVE-2023-52111HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2023-4812HigJan 12, 2024
    risk 0.49cvss 7.6epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously…

  • CVE-2023-5644HigDec 26, 2023
    risk 0.49cvss 7.6epss 0.01

    The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

  • CVE-2023-49246HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49240HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49239HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49947HigDec 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.

  • CVE-2023-5553HigNov 21, 2023
    risk 0.49cvss 7.6epss 0.00

    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no…

  • CVE-2023-46992HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.

  • CVE-2023-45899HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.

  • CVE-2023-40829HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.00

    There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.

  • CVE-2023-30995HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268.

  • CVE-2023-39384HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-37491HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious…

  • CVE-2023-32783HigAug 7, 2023
    risk 0.49cvss 7.5epss 0.04

    The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."

  • CVE-2023-36339HigJul 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request.