CWE-285
1,562 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,562)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (m...Show more |
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Sep 10, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems...Show more |
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119...Show more |
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter. |
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized. |
1Cisco 2Prime Collaboration Prime Collaboration ProvisioningNov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient v...Show more |
1Opensuse 1Open Build Service Nov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689. |
1Opensuse 1Open Build Service Nov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links. |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 27, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an...Show more |
2Hawt Redhat2Hawtio Jboss FuseNov 21, 2024 Jul 26, 2018 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which me...Show more |
3Debian Fuse ProjectRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 24, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option rega...Show more |
1Cisco 3Mobility Services Engine 3310 Firmware Mobility Services Engine 3355 FirmwareMobility Services Engine 3365 FirmwareNov 21, 2024 Jul 18, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability i...Show more |
3Canonical DebianPolkit Project3Debian Linux PolkitUbuntu LinuxNov 21, 2024 Jul 10, 2018 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unre...Show more |
4Ceph DebianOpensuse+1 more9Ceph Ceph StorageCeph Storage Mon+6 moreNov 21, 2024 Jul 10, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous...Show more |
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode. |
1Redhat 4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreNov 21, 2024 Jul 3, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow acces...Show more |
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryptio...Show more |
1Sybase 1Adaptive Server Enterprise Nov 21, 2024 Apr 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859...Show more |
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site. |