CWE-863
2,983 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (2,983)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py. |
1Pivotal Software 1Cloud Foundry Uaa Nov 21, 2024 Jul 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, incorrectly authorizes requests to admin endpoints by accepting a valid re...Show more |
Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full access to privileged database functions. Sage XRT Treasury is a business...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress a...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds. |
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted...Show more |
1Emc 1Rsa Identity Governance And Lifecycle Nov 21, 2024 Jul 13, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin pri...Show more |
1Adbglobal 4Dv2210 Firmware Prg Av4202n FirmwareVv2220 Firmware+1 moreNov 21, 2024 Jul 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forb...Show more |
2D Link Dlink3Dir 885l/r Firmware Dir 890l FirmwareDir 895l/r FirmwareNov 21, 2024 Jul 5, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/R with firmware 1.21B04beta04 and earlier devices (all hardware revisio...Show more |
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode. |
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerability exists because the...Show more |
Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter. |
When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execu...Show more |
1Cisco 1Unified Computing System Nov 21, 2024 Jun 7, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system. The vulnerab...Show more |
An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin c...Show more |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This restriction can be bypassed by modifying the...Show more |
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the control...Show more |
1Ibm 8San Volume Controller Firmware Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 moreNov 21, 2024 May 17, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more |
1Ibm 8San Volume Controller Firmware Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 moreNov 21, 2024 May 17, 2018 N/A· v4 7.6 HIGH· v3 6.5 MEDIUM· v2 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more |
1Pivotal Software 1Pivotal Application Service Nov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to...Show more |