CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 57 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12876 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2020 | Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments. | ||
| CVE-2020-12477 | Hig | 0.49 | 7.5 | 0.02 | Apr 29, 2020 | The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function. | ||
| CVE-2018-21039 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka QuickTools), an attacker can bypass the lockscreen. The Samsung ID is SVE-2018-12053 (December 2018). | ||
| CVE-2020-5318 | Hig | 0.49 | 7.5 | 0.01 | Feb 6, 2020 | Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The non-RAN HTTP and WebDAV file-serving components have a vulnerability wherein… | ||
| CVE-2012-3822 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2020 | Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials. | ||
| CVE-2019-20213 | Hig | 0.49 | 7.5 | 0.02 | Jan 2, 2020 | D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php. | ||
| CVE-2018-20494 | Hig | 0.49 | 7.5 | 0.02 | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control. | ||
| CVE-2013-4410 | Hig | 0.49 | 7.5 | 0.02 | Dec 2, 2019 | ReviewBoard: has an access-control problem in REST API | ||
| CVE-2011-2726 | Hig | 0.49 | 7.5 | 0.02 | Nov 15, 2019 | An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent… | ||
| CVE-2019-18949 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2019 | SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration. | ||
| CVE-2009-3723 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2019 | asterisk allows calls on prohibited networks | ||
| CVE-2019-17191 | Hig | 0.49 | 7.5 | 0.02 | Oct 5, 2019 | The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the… | ||
| CVE-2019-6836 | Hig | 0.49 | 7.5 | 0.01 | Sep 17, 2019 | A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow the… | ||
| CVE-2019-15729 | Hig | 0.49 | 7.5 | 0.02 | Sep 17, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request. | ||
| CVE-2019-13337 | Hig | 0.49 | 7.5 | 0.01 | Jul 9, 2019 | In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic… | ||
| CVE-2019-3399 | Hig | 0.49 | 7.5 | 0.02 | Apr 30, 2019 | The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check. | ||
| CVE-2019-3842 | Hig | 0.49 | 7.0 | 0.01 | Apr 9, 2019 | In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be… | ||
| CVE-2018-17950 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2018 | Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 | ||
| CVE-2018-14748 | Hig | 0.49 | 7.5 | 0.01 | Nov 28, 2018 | Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS. | ||
| CVE-2018-16620 | Hig | 0.49 | 7.5 | 0.01 | Nov 15, 2018 | Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control. |
- risk 0.49cvss 7.5epss 0.01
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.
- risk 0.49cvss 7.5epss 0.02
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka QuickTools), an attacker can bypass the lockscreen. The Samsung ID is SVE-2018-12053 (December 2018).
- risk 0.49cvss 7.5epss 0.01
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The non-RAN HTTP and WebDAV file-serving components have a vulnerability wherein…
- risk 0.49cvss 7.5epss 0.02
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.
- risk 0.49cvss 7.5epss 0.02
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
- risk 0.49cvss 7.5epss 0.02
ReviewBoard: has an access-control problem in REST API
- risk 0.49cvss 7.5epss 0.02
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent…
- risk 0.49cvss 7.5epss 0.01
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
- risk 0.49cvss 7.5epss 0.01
asterisk allows calls on prohibited networks
- risk 0.49cvss 7.5epss 0.02
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the…
- risk 0.49cvss 7.5epss 0.01
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow the…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.
- risk 0.49cvss 7.5epss 0.01
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic…
- risk 0.49cvss 7.5epss 0.02
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
- risk 0.49cvss 7.0epss 0.01
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be…
- risk 0.49cvss 7.5epss 0.01
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
- risk 0.49cvss 7.5epss 0.01
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.
- risk 0.49cvss 7.5epss 0.01
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.