CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 53 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27138 | Hig | 0.49 | 7.5 | 0.01 | Mar 1, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache… | ||
| CVE-2023-52374 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2024 | Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52361 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2024 | The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity. | ||
| CVE-2023-47142 | Hig | 0.49 | 7.5 | 0.00 | Feb 2, 2024 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267. | ||
| CVE-2023-52111 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2023-4812 | Hig | 0.49 | 7.6 | 0.01 | Jan 12, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously… | ||
| CVE-2023-5644 | Hig | 0.49 | 7.6 | 0.01 | Dec 26, 2023 | The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users. | ||
| CVE-2023-49246 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49240 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49239 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-49947 | Hig | 0.49 | 7.5 | 0.01 | Dec 3, 2023 | Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication. | ||
| CVE-2023-5553 | Hig | 0.49 | 7.6 | 0.00 | Nov 21, 2023 | During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no… | ||
| CVE-2023-46992 | Hig | 0.49 | 7.5 | 0.01 | Oct 31, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages. | ||
| CVE-2023-45899 | Hig | 0.49 | 7.5 | 0.01 | Oct 31, 2023 | An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call. | ||
| CVE-2023-40829 | Hig | 0.49 | 7.5 | 0.00 | Oct 12, 2023 | There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000. | ||
| CVE-2023-30995 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2023 | IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268. | ||
| CVE-2023-39384 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-37491 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2023 | The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious… | ||
| CVE-2023-32783 | Hig | 0.49 | 7.5 | 0.04 | Aug 7, 2023 | The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour." | ||
| CVE-2023-36339 | Hig | 0.49 | 7.5 | 0.01 | Jul 21, 2023 | An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request. |
- risk 0.49cvss 7.5epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache…
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.
- risk 0.49cvss 7.5epss 0.00
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.
- risk 0.49cvss 7.5epss 0.00
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
- risk 0.49cvss 7.6epss 0.01
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously…
- risk 0.49cvss 7.6epss 0.01
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
- risk 0.49cvss 7.6epss 0.00
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no…
- risk 0.49cvss 7.5epss 0.01
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.
- risk 0.49cvss 7.5epss 0.01
An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.
- risk 0.49cvss 7.5epss 0.00
There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.
- risk 0.49cvss 7.5epss 0.01
IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.49cvss 7.5epss 0.01
The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious…
- risk 0.49cvss 7.5epss 0.04
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
- risk 0.49cvss 7.5epss 0.01
An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request.