← Back
CWE-285

1,431 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,431)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Adaptive Security Appliance Software
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using t...Show more
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.Show less
1Redhat
1Keycloak
Nov 21, 2024
Nov 30, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
1Vecna
1Vgo Firmware
Nov 21, 2024
Oct 30, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their privileges and within th...Show more
VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their privileges and within the scope of an admin account. If an attacker has access to VGo XAMPP Client credentials, they may be able to execute admin commands on the connected robot.Show less
1Projectsend
1Projectsend
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
1Cisco
1Ucs Director
Nov 21, 2024
Oct 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive informati...Show more
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to an authorization check that does not properly include the access level of the web interface user. An attacker who has valid application credentials could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional reconnaissance attacks.Show less
1Cisco
1Network Functions Virtualization Infrastructure
Nov 21, 2024
Oct 5, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient autho...Show more
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks. An attacker could exploit this vulnerability by sending a malicious API request with the authentication credentials of a low-privileged user. A successful exploit could allow the attacker to read any file on the affected system.Show less
1Cisco
1Network Functions Virtualization Infrastructure
Nov 21, 2024
Oct 5, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerab...Show more
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server-side authorization checks. An attacker who is logged in to the web-based management interface as a low-privileged user could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to use the low-privileged user account to reboot or shut down the affected system.Show less
1Elastic
1Elastic Cloud Enterprise
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP addres...Show more
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other clusters data.Show less
2Clusterlabs
Redhat
3Enterprise Linux Server
Enterprise Linux Server EusPacemaker
Nov 21, 2024
Sep 10, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the L...Show more
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.Show less
1Theforeman
1Foreman
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (m...Show more
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.Show less
1Theforeman
1Foreman
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less...Show more
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.Show less
1Redhat
2Cloudforms
Cloudforms Management Engine
Nov 21, 2024
Sep 10, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems...Show more
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.Show less
1Ibm
1Urbancode Deploy
Nov 21, 2024
Aug 30, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119...Show more
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.Show less
1Phpmyfaq
1Phpmyfaq
Nov 21, 2024
Aug 28, 2018
N/A· v4
2.7 LOW· v3
5.5 MEDIUM· v2
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
1Aedes Project
1Aedes
Nov 21, 2024
Aug 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
1Cisco
2Prime Collaboration
Prime Collaboration Provisioning
Nov 21, 2024
Aug 1, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient v...Show more
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient validation of a password change request. An attacker could exploit this vulnerability by changing a specific administrator account password. A successful exploit could allow the attacker to cause the affected device to become inoperable, resulting in a denial of service (DoS) condition. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.2 and prior. Cisco Bug IDs: CSCvd86586.Show less
1Opensuse
1Open Build Service
Nov 21, 2024
Aug 1, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
1Opensuse
1Open Build Service
Nov 21, 2024
Aug 1, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
1Redhat
2Cloudforms
Cloudforms Management Engine
Nov 21, 2024
Jul 27, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an...Show more
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.Show less
2Hawt
Redhat
2Hawtio
Jboss Fuse
Nov 21, 2024
Jul 26, 2018
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which me...Show more
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.Show less