VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 68 of 187
  • CVE-2023-31138HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.01

    DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, using object model traversal in the payload of a PATCH request, authenticated users with write…

  • CVE-2023-23696HigFeb 7, 2023
    risk 0.46cvss 7.0epss 0.00

    Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system.

  • CVE-2023-22480HigJan 14, 2023
    risk 0.46cvss 7.3epss 0.67

    KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This…

  • CVE-2022-23451HigSep 6, 2022
    risk 0.46cvss 8.1epss 0.01

    An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete…

  • CVE-2022-1401MedAug 17, 2022
    risk 0.46cvss 6.9epss 0.18

    Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.

  • CVE-2022-31107HigJul 15, 2022
    risk 0.46cvss 7.1epss 0.03

    Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take…

  • CVE-2021-3456HigMar 30, 2022
    risk 0.46cvss 7.1epss 0.00

    An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and…

  • CVE-2022-24721HigMar 15, 2022
    risk 0.46cvss 8.1epss 0.01

    CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal usage of Oort and Seti channels is improperly authorized, so any remote user could subscribe and publish to those channels. By subscribing to those channels, a…

  • CVE-2021-20119HigNov 9, 2021
    risk 0.46cvss 7.1epss 0.00

    The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.

  • CVE-2021-38345HigOct 14, 2021
    risk 0.46cvss 7.1epss 0.01

    The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was…

  • CVE-2021-38312HigSep 2, 2021
    risk 0.46cvss 7.1epss 0.01

    The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback`…

  • CVE-2021-24405MedJul 6, 2021
    risk 0.46cvss 6.5epss 0.11

    The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If users can't register, this can be done through CSRF. Furthermore, the cookie banner…

  • CVE-2021-25410HigJun 11, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.

  • CVE-2021-1086HigApr 29, 2021
    risk 0.46cvss 7.1epss 0.00

    NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control unauthorized resources, which may lead to integrity and confidentiality loss or information disclosure. This affects vGPU version 12.x (prior to 12.2), version…

  • CVE-2021-25356HigApr 9, 2021
    risk 0.46cvss 7.1epss 0.00

    An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.

  • CVE-2021-20179HigMar 15, 2021
    risk 0.46cvss 8.1epss 0.01

    A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and…

  • CVE-2021-26964HigMar 5, 2021
    risk 0.46cvss 7.1epss 0.01

    A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to improperly access and modify…

  • CVE-2016-6591HigJan 8, 2020
    risk 0.46cvss 7.1epss 0.00

    A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.

  • CVE-2019-11247HigAug 29, 2019
    risk 0.46cvss 8.1epss 0.02

    The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning…

  • CVE-2019-10964HigJun 28, 2019
    risk 0.46cvss 7.1epss 0.01

    Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or…