CWE-863
2,989 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (2,989)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 1Sinema Remote Connect Server Nov 21, 2024 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization se...Show more |
3Dogtagpki FedoraprojectRedhat4Certificate System DogtagpkiEnterprise Linux+1 moreNov 21, 2024 Mar 15, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat...Show more |
The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the git master branch for a short time. Howe...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Nov 21, 2024 Mar 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login). |
2Elementary Fedoraproject2Fedora Switchboard Bluetooth PlugNov 21, 2024 Mar 12, 2021 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service...Show more |
In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to local information disclosure with no additional execution privileges nee...Show more |
In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass. This could lead to local escalation of privilege with no additional executi...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraNov 21, 2024 Mar 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraNov 21, 2024 Mar 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. |
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind. |
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects,...Show more |
2Elastic Oracle2Communications Cloud Native Core Automated Test Suite ElasticsearchNov 21, 2024 Mar 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query a...Show more |
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly poli...Show more |
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All vers...Show more |
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary...Show more |
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an aut...Show more |
A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak....Show more |
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article. |
1Dataiku 1Data Science Studio Nov 21, 2024 Mar 1, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJan 14, 2025 Feb 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. |