VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 93 of 187
  • CVE-2025-1214MedFeb 12, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of the component Role-Based Access Control. The manipulation leads to missing authorization. It is possible to initiate the attack…

  • CVE-2024-9082MedSep 22, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save of the component User Creation Handler. The manipulation of the argument Type with the…

  • CVE-2024-43954MedAug 29, 2024
    risk 0.41cvss 6.3epss 0.00

    Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from n/a through 1.1.1.

  • CVE-2024-6358MedAug 6, 2024
    risk 0.41cvss 6.3epss 0.00

    Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

  • CVE-2022-29946MedJul 11, 2024
    risk 0.41cvss 6.3epss 0.00

    NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit…

  • CVE-2024-39871MedJul 9, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the…

  • CVE-2024-1677MedMay 2, 2024
    risk 0.41cvss 6.3epss 0.01

    The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all…

  • CVE-2024-27309HigApr 12, 2024
    risk 0.41cvss 7.4epss 0.01

    While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated with the removed ACL…

  • CVE-2023-47716MedMar 1, 2024
    risk 0.41cvss 6.3epss 0.00

    IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656.

  • CVE-2023-40610MedNov 27, 2023
    risk 0.41cvss 6.3epss 0.01

    Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially…

  • CVE-2023-43508MedOct 25, 2023
    risk 0.41cvss 6.3epss 0.00

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of these vulnerabilities allow an attacker…

  • CVE-2023-34035HigJul 18, 2023
    risk 0.41cvss 7.3epss 0.01

    Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s…

  • CVE-2023-25594MedMar 22, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker…

  • CVE-2022-1499MedJul 26, 2022
    risk 0.41cvss 6.3epss 0.01

    Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • CVE-2021-35526MedSep 8, 2021
    risk 0.41cvss 6.3epss 0.00

    Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6…

  • CVE-2021-24282MedMay 14, 2021
    risk 0.41cvss 6.3epss 0.01

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s…

  • CVE-2020-27901MedApr 2, 2021
    risk 0.41cvss 6.3epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2021-1270MedJan 20, 2021
    risk 0.41cvss 6.3epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the…

  • CVE-2021-1269MedJan 20, 2021
    risk 0.41cvss 6.3epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the…

  • CVE-2020-3522MedAug 26, 2020
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the device. The…