CWE-863
3,038 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,038)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests. |
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks. |
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an aut...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Jun 27, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows inter...Show more |
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator...Show more |
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker co...Show more |
1Jenkins 1Embeddable Build Status Nov 21, 2024 Jun 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any p...Show more |
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands whe...Show more |
1Adminer Login Project 1Adminer Login Nov 21, 2024 Jun 20, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the...Show more |
ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service. |
1Sap 3Erp Financial Accounting Erp Localization For Cee CountriesS/4hanaNov 21, 2024 Jun 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to user...Show more |
1Sap 4Netweaver As Abap Netweaver As Abap Krnl64nucNetweaver As Abap Krnl64uc+1 moreNov 21, 2024 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions...Show more |
1Qualcomm 107Apq8009w Firmware Aqt1000 FirmwareAr8031 Firmware+104 moreNov 21, 2024 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Sn...Show more |
1Powertekpdus 7Basic Pdu Firmware Piml Pdu FirmwarePm Pdu Firmware+4 moreNov 21, 2024 Jun 13, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the da...Show more |
1Festo 8Controller Cecc X M1 Mv S1 Firmware Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 moreNov 21, 2024 Jun 13, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with...Show more |
1Festo 8Controller Cecc X M1 Mv S1 Firmware Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 moreNov 21, 2024 Jun 13, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with...Show more |
1Festo 8Controller Cecc X M1 Mv S1 Firmware Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 moreNov 21, 2024 Jun 13, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system command...Show more |
1Festo 8Controller Cecc X M1 Mv S1 Firmware Controller Cecc X M1 Mv FirmwareController Cecc X M1 Y Yjkp Firmware+5 moreNov 21, 2024 Jun 13, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands...Show more |
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with...Show more |
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possessio...Show more |