VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 89 of 187
  • CVE-2020-6362MedOct 20, 2020
    risk 0.42cvss 6.5epss 0.01

    SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to privilege escalation and violation in segregation of…

  • CVE-2020-15664MedOct 1, 2020
    risk 0.42cvss 6.5epss 0.01

    By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended…

  • CVE-2020-13284MedSep 14, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

  • CVE-2020-6311MedSep 9, 2020
    risk 0.42cvss 6.5epss 0.01

    Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorization checks, that may cause a system…

  • CVE-2020-24941HigSep 4, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.

  • CVE-2020-7499MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized changes.

  • CVE-2020-4249MedMay 28, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to incorrect authorization. IBM X-Force ID: 175485.

  • CVE-2020-8151HigMay 12, 2020
    risk 0.42cvss 7.5epss 0.02

    There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.

  • CVE-2020-5275HigMar 30, 2020
    risk 0.42cvss 7.6epss 0.01

    In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that…

  • CVE-2020-5240HigMar 13, 2020
    risk 0.42cvss 7.6epss 0.01

    In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA…

  • CVE-2019-5474MedJan 28, 2020
    risk 0.42cvss 6.5epss 0.01

    An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

  • CVE-2014-0169MedJan 2, 2020
    risk 0.42cvss 6.5epss 0.01

    In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization.…

  • CVE-2019-4343MedDec 30, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422.

  • CVE-2016-6353MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.

  • CVE-2016-3131MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

  • CVE-2011-3617MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

  • CVE-2019-5879MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

  • CVE-2015-1780MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.01

    oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

  • CVE-2012-2238HigNov 21, 2019
    risk 0.42cvss 7.5epss 0.02

    trytond 2.4: ModelView.button fails to validate authorization

  • CVE-2019-6144MedOct 23, 2019
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.