VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 79 of 209
  • CVE-2024-54916MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.

  • CVE-2025-24401MedJan 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality…

  • CVE-2024-48911HigOct 14, 2024
    risk 0.44cvss 7.8epss 0.00

    OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s possible for the unprivileged user to change…

  • CVE-2024-9136MedSep 27, 2024
    risk 0.44cvss 6.7epss 0.00

    Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-6979MedSep 10, 2024
    risk 0.44cvss 6.8epss 0.00

    Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute,…

  • CVE-2024-5714MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.01

    In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project identifiers in requests, enabling them to invite users to projects in other organizations, change members to projects in other…

  • CVE-2024-3331MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user…

  • CVE-2024-0160MedJun 12, 2024
    risk 0.44cvss 6.8epss 0.00

    Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

  • CVE-2024-36365MedMay 29, 2024
    risk 0.44cvss 6.8epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

  • CVE-2023-6355MedDec 18, 2023
    risk 0.44cvss 6.8epss 0.00

    Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. This issue affects: Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507 (MR1)), 8.90 prior to…

  • CVE-2023-24047MedDec 4, 2023
    risk 0.44cvss 6.8epss 0.00

    An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.

  • CVE-2023-1832MedOct 4, 2023
    risk 0.44cvss 6.8epss 0.01

    An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

  • CVE-2023-34724MedAug 28, 2023
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the UART interface.

  • CVE-2023-4107MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.01

    Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.

  • CVE-2022-29871MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-30705MedAug 10, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.

  • CVE-2023-3033MedJun 2, 2023
    risk 0.44cvss 6.8epss 0.01

    Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22.

  • CVE-2023-2002MedMay 26, 2023
    risk 0.44cvss 6.8epss 0.01

    A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and…

  • CVE-2023-21116MedMay 15, 2023
    risk 0.44cvss 6.7epss 0.00

    In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…

  • CVE-2023-20880MedMay 12, 2023
    risk 0.44cvss 6.7epss 0.00

    VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.