CWE-862
8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges. |
1Sap 1Enterprise Financial Services Nov 21, 2024 Sep 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary authorization checks for an authenticated user, resulting in escalation...Show more |
1Sap 1Enterprise Financial Services Nov 21, 2024 Sep 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of...Show more |
1Furuno 2Felcom 250 Firmware Felcom 500 FirmwareNov 21, 2024 Sep 10, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Aug 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to de...Show more |
An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table...Show more |
A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions...Show more |
1F5 1Big Ip Access Policy Manager Client Jun 17, 2026 Aug 17, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy logon mode which uses a SYSTEM account to establish network access. This feature displays a certificat...Show more |
1Pleasantsolutions 1Pleasant Password Server Nov 21, 2024 Jul 31, 2018 N/A· v4 8.1 HIGH· v3 6.5 MEDIUM· v2 Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To perform those actions on an entry, the user...Show more |
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 26, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is trigge...Show more |
3Canonical DebianPolkit Project3Debian Linux PolkitUbuntu LinuxNov 21, 2024 Jul 10, 2018 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unre...Show more |
Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
1Ribboncommunications 3Sbc Swe Lite Web Sonus Sbc 1000 FirmwareSonus Sbc 2000 FirmwareNov 21, 2024 Jul 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0...Show more |
NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downloading this file, an attacker can access the admin password, WPA key, and any config information of...Show more |
1Opensuse 1Open Build Service Nov 21, 2024 Jun 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16. |
WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivil...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by...Show more |
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data. |
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulnerability is due to ins...Show more |