VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 67 of 187
  • CVE-2024-3379HigNov 14, 2024
    risk 0.46cvss 8.1epss 0.00

    In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private…

  • CVE-2024-45164HigNov 4, 2024
    risk 0.46cvss 7.1epss 0.00

    Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert…

  • CVE-2024-21285HigOct 15, 2024
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via…

  • CVE-2024-21284HigOct 15, 2024
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via…

  • CVE-2024-47183HigOct 4, 2024
    risk 0.46cvss 8.1epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the…

  • CVE-2024-8691HigSep 11, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are…

  • CVE-2024-41964HigAug 29, 2024
    risk 0.46cvss 8.1epss 0.00

    Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for creating and deleting languages have already existed and could be configured, but were not…

  • CVE-2024-43250HigAug 19, 2024
    risk 0.46cvss 7.1epss 0.00

    Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a through 2.6.4.

  • CVE-2024-37300HigJun 12, 2024
    risk 0.46cvss 8.1epss 0.00

    OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub…

  • CVE-2024-31452HigApr 16, 2024
    risk 0.46cvss 8.1epss 0.01

    OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model involves exclusion (e.g. `a but not b`)…

  • CVE-2024-27933HigMar 21, 2024
    risk 0.46cvss 8.2epss 0.02

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature close of arbitrary file descriptors, allowing standard input to be re-opened as a different resource resulting in permission…

  • CVE-2024-1482HigFeb 14, 2024
    risk 0.46cvss 7.1epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub Actions workflows with permissions from the GITHUB_TOKEN. To exploit this vulnerability, an…

  • CVE-2023-47320HigDec 13, 2023
    risk 0.46cvss 8.1epss 0.01

    Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users.…

  • CVE-2023-6542HigDec 12, 2023
    risk 0.46cvss 7.1epss 0.00

    Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to…

  • CVE-2022-40681HigNov 14, 2023
    risk 0.46cvss 7.1epss 0.00

    A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to cause denial of service via sending a crafted request to a specific named pipe.

  • CVE-2023-4379HigNov 9, 2023
    risk 0.46cvss 8.1epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.

  • CVE-2023-4814HigSep 14, 2023
    risk 0.46cvss 7.1epss 0.00

    A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to.

  • CVE-2023-28175HigJun 15, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.

  • CVE-2022-40529HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Memory corruption due to improper access control in kernel while processing a mapping request from root process.

  • CVE-2020-23362HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.01

    Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.