CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 89 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-6362 | Med | 0.42 | 6.5 | 0.01 | Oct 20, 2020 | SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to privilege escalation and violation in segregation of… | ||
| CVE-2020-15664 | Med | 0.42 | 6.5 | 0.01 | Oct 1, 2020 | By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended… | ||
| CVE-2020-13284 | Med | 0.42 | 6.5 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token | ||
| CVE-2020-6311 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2020 | Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorization checks, that may cause a system… | ||
| CVE-2020-24941 | Hig | 0.42 | 7.5 | 0.01 | Sep 4, 2020 | An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions. | ||
| CVE-2020-7499 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2020 | A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized changes. | ||
| CVE-2020-4249 | Med | 0.42 | 6.5 | 0.01 | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to incorrect authorization. IBM X-Force ID: 175485. | ||
| CVE-2020-8151 | Hig | 0.42 | 7.5 | 0.02 | May 12, 2020 | There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information. | ||
| CVE-2020-5275 | Hig | 0.42 | 7.6 | 0.01 | Mar 30, 2020 | In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that… | ||
| CVE-2020-5240 | Hig | 0.42 | 7.6 | 0.01 | Mar 13, 2020 | In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA… | ||
| CVE-2019-5474 | Med | 0.42 | 6.5 | 0.01 | Jan 28, 2020 | An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions. | ||
| CVE-2014-0169 | Med | 0.42 | 6.5 | 0.01 | Jan 2, 2020 | In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization.… | ||
| CVE-2019-4343 | Med | 0.42 | 6.5 | 0.01 | Dec 30, 2019 | IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422. | ||
| CVE-2016-6353 | Med | 0.42 | 6.5 | 0.01 | Nov 26, 2019 | Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler. | ||
| CVE-2016-3131 | Med | 0.42 | 6.5 | 0.01 | Nov 26, 2019 | Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. | ||
| CVE-2011-3617 | Med | 0.42 | 6.5 | 0.01 | Nov 26, 2019 | Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases. | ||
| CVE-2019-5879 | Med | 0.42 | 6.5 | 0.01 | Nov 25, 2019 | Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension. | ||
| CVE-2015-1780 | Med | 0.42 | 6.5 | 0.01 | Nov 22, 2019 | oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center | ||
| CVE-2012-2238 | Hig | 0.42 | 7.5 | 0.02 | Nov 21, 2019 | trytond 2.4: ModelView.button fails to validate authorization | ||
| CVE-2019-6144 | Med | 0.42 | 6.5 | 0.01 | Oct 23, 2019 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection. |
- risk 0.42cvss 6.5epss 0.01
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to privilege escalation and violation in segregation of…
- risk 0.42cvss 6.5epss 0.01
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended…
- risk 0.42cvss 6.5epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token
- risk 0.42cvss 6.5epss 0.01
Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorization checks, that may cause a system…
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.
- risk 0.42cvss 6.5epss 0.01
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized changes.
- risk 0.42cvss 6.5epss 0.01
IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to incorrect authorization. IBM X-Force ID: 175485.
- risk 0.42cvss 7.5epss 0.02
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
- risk 0.42cvss 7.6epss 0.01
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that…
- risk 0.42cvss 7.6epss 0.01
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA…
- risk 0.42cvss 6.5epss 0.01
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
- risk 0.42cvss 6.5epss 0.01
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization.…
- risk 0.42cvss 6.5epss 0.01
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422.
- risk 0.42cvss 6.5epss 0.01
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
- risk 0.42cvss 6.5epss 0.01
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
- risk 0.42cvss 6.5epss 0.01
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
- risk 0.42cvss 6.5epss 0.01
Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
- risk 0.42cvss 6.5epss 0.01
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
- risk 0.42cvss 7.5epss 0.02
trytond 2.4: ModelView.button fails to validate authorization
- risk 0.42cvss 6.5epss 0.01
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.