VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 72 of 187
  • CVE-2023-3033MedJun 2, 2023
    risk 0.44cvss 6.8epss 0.01

    Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22.

  • CVE-2023-2002MedMay 26, 2023
    risk 0.44cvss 6.8epss 0.01

    A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and…

  • CVE-2023-21116MedMay 15, 2023
    risk 0.44cvss 6.7epss 0.00

    In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…

  • CVE-2023-20880MedMay 12, 2023
    risk 0.44cvss 6.7epss 0.00

    VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

  • CVE-2023-24932MedMay 9, 2023
    risk 0.44cvss 6.7epss 0.11

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2023-28270MedApr 11, 2023
    risk 0.44cvss 6.8epss 0.00

    Windows Lock Screen Security Feature Bypass Vulnerability

  • CVE-2022-45435MedJan 31, 2023
    risk 0.44cvss 6.8epss 0.00

    IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior versions allow authenticated users…

  • CVE-2022-39913MedDec 8, 2022
    risk 0.44cvss 6.8epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.

  • CVE-2022-3048MedSep 26, 2022
    risk 0.44cvss 6.8epss 0.00

    Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.

  • CVE-2022-29854MedMay 13, 2022
    risk 0.44cvss 6.8epss 0.01

    A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system…

  • CVE-2022-23822MedApr 27, 2022
    risk 0.44cvss 6.8epss 0.00

    In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as…

  • CVE-2022-28542MedApr 11, 2022
    risk 0.44cvss 6.8epss 0.00

    Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.

  • CVE-2021-39234MedNov 19, 2021
    risk 0.44cvss 6.8epss 0.01

    In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

  • CVE-2020-16630MedSep 20, 2021
    risk 0.44cvss 6.8epss 0.01

    TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim…

  • CVE-2021-28696MedAug 27, 2021
    risk 0.44cvss 6.8epss 0.00

    IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically…

  • CVE-2021-22521MedJul 30, 2021
    risk 0.44cvss 6.7epss 0.00

    A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.

  • CVE-2010-2525HigJun 22, 2021
    risk 0.44cvss 7.8epss 0.00

    A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file system.

  • CVE-2021-28164MedApr 1, 2021
    risk 0.44cvss 5.3epss 0.82

    In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the…

  • CVE-2021-27099MedMar 5, 2021
    risk 0.44cvss 6.8epss 0.01

    In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker…

  • CVE-2020-17049MedNov 11, 2020
    risk 0.44cvss 6.6epss 0.14

    A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could…