VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 81 of 187
  • CVE-2024-57677MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.

  • CVE-2024-57676MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

  • CVE-2025-21403MedJan 14, 2025
    risk 0.42cvss 6.4epss 0.01

    On-Premises Data Gateway Information Disclosure Vulnerability

  • CVE-2024-56114MedJan 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit…

  • CVE-2024-39025HigDec 27, 2024
    risk 0.42cvss 7.5epss 0.00

    Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.

  • CVE-2024-51479HigDec 17, 2024
    risk 0.42cvss 7.5epss 0.04

    Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root…

  • CVE-2024-12196MedDec 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.

  • CVE-2024-42451MedDec 4, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side.…

  • CVE-2024-36611HigNov 29, 2024
    risk 0.42cvss 7.5epss 0.01

    In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper…

  • CVE-2024-48651HigNov 29, 2024
    risk 0.42cvss 7.5epss 0.02

    In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

  • CVE-2024-11669MedNov 26, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

  • CVE-2022-31669MedNov 14, 2024
    risk 0.42cvss 6.4epss 0.00

    Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag…

  • CVE-2022-31667MedNov 14, 2024
    risk 0.42cvss 6.4epss 0.01

    Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name…

  • CVE-2024-45877MedNov 13, 2024
    risk 0.42cvss 6.5epss 0.00

    baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of…

  • CVE-2024-44765MedNov 8, 2024
    risk 0.42cvss 6.5epss 0.01

    An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.

  • CVE-2024-20537MedNov 6, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to a lack of server-side validation of Administrator…

  • CVE-2024-20482MedOct 23, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploit this…

  • CVE-2024-49209MedOct 22, 2024
    risk 0.42cvss 6.5epss 0.00

    Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit this vulnerability to elevate their privileges and upload additional system…

  • CVE-2024-21262MedOct 15, 2024
    risk 0.42cvss 6.5epss 0.01

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2024-45132MedOct 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect…