← Back
CWE-285

1,562 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,562)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
2Debian
Gitlab
2Debian Linux
Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.
1Ibm
1Business Process Manager
Nov 21, 2024
Mar 15, 2018
N/A· v4
4.3 MEDIUM· v3
5.5 MEDIUM· v2
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID:...Show more
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.Show less
1Freeipa
1Freeipa
Nov 21, 2024
Mar 13, 2018
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker c...Show more
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.Show less
1Opensuse
1Open Build Service
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions l...Show more
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).Show less
1Trendmicro
1Smart Protection Server
Nov 21, 2024
Jan 19, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authentica...Show more
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.Show less
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
Jan 12, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP...Show more
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.Show less
1Redhat
1Keycloak
May 13, 2026
Oct 26, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker...Show more
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.Show less
1Redhat
1Pagure
May 13, 2026
Sep 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
1Arubanetworks
1Clearpass
May 13, 2026
Aug 29, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.
1Sierra Wireless
2Airlink Raven Xe Firmware
Airlink Raven Xt Firmware
May 13, 2026
Jun 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without...Show more
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.Show less
1Elastic
1Kibana
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when...Show more
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.Show less
1Google
1Android
May 13, 2026
Jun 6, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
1Google
1Android
May 13, 2026
Jun 6, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
1Zulip
1Zulip Server
May 13, 2026
Jun 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Z...Show more
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.Show less
1Postgresql
1Postgresql
May 13, 2026
May 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing inf...Show more
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.Show less
1Nextcloud
1Nextcloud Server
May 13, 2026
May 8, 2017
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
1Nextcloud
1Nextcloud Server
May 13, 2026
May 8, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the...Show more
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.Show less
1Nextcloud
1Nextcloud Server
May 13, 2026
May 8, 2017
N/A· v4
3.5 LOW· v3
4.3 MEDIUM· v2
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.
1Bmc
1Server Automation
May 13, 2026
May 2, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.