CWE-285
1,431 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,431)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Adaptive Security Appliance Software Nov 21, 2024 Dec 24, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using t...Show more |
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack. |
VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their privileges and within th...Show more |
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. |
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive informati...Show more |
1Cisco 1Network Functions Virtualization Infrastructure Nov 21, 2024 Oct 5, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient autho...Show more |
1Cisco 1Network Functions Virtualization Infrastructure Nov 21, 2024 Oct 5, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerab...Show more |
1Elastic 1Elastic Cloud Enterprise Nov 21, 2024 Sep 19, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP addres...Show more |
2Clusterlabs Redhat3Enterprise Linux Server Enterprise Linux Server EusPacemakerNov 21, 2024 Sep 10, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the L...Show more |
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (m...Show more |
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Sep 10, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems...Show more |
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119...Show more |
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter. |
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized. |
1Cisco 2Prime Collaboration Prime Collaboration ProvisioningNov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient v...Show more |
1Opensuse 1Open Build Service Nov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689. |
1Opensuse 1Open Build Service Nov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links. |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 27, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an...Show more |
2Hawt Redhat2Hawtio Jboss FuseNov 21, 2024 Jul 26, 2018 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which me...Show more |