VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 54 of 187
  • CVE-2022-48508HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2023-34161HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-22248HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to leak another user's data.…

  • CVE-2023-33651HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.

  • CVE-2023-22833HigJun 6, 2023
    risk 0.49cvss 7.6epss 0.00

    Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.

  • CVE-2023-31226HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-31726HigMay 23, 2023
    risk 0.49cvss 7.5epss 0.01

    AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.

  • CVE-2023-23299HigMay 23, 2023
    risk 0.49cvss 7.5epss 0.01

    The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and…

  • CVE-2023-23446HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

  • CVE-2023-23445HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

  • CVE-2023-2534HigMay 8, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by…

  • CVE-2023-30467HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by…

  • CVE-2021-23203HigApr 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.

  • CVE-2023-22620HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative…

  • CVE-2023-23918HigFeb 23, 2023
    risk 0.49cvss 7.5epss 0.02

    A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using…

  • CVE-2023-22500HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This vulnerability allow unauthorized access to inventory files. Thus, if anonymous access to FAQ is allowed, inventory files are…

  • CVE-2022-46076HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.

  • CVE-2022-36785HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.02

    D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at line 15 "login.asp" A. The window.location.href = http://192.168.1.1/setupWizard.asp" http://192.168.1.1/setupWizard.asp" ;…

  • CVE-2022-42978HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.

  • CVE-2022-41574HigOct 7, 2022
    risk 0.49cvss 7.5epss 0.01

    An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally…