← Back
CWE-863

3,308 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Jira
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-...Show more
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Microsoft
6Windows 10
Windows 8.1Windows Rt 8.1+3 more
Jun 17, 2026
Jan 8, 2019
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windo...Show more
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.Show less
1Zte
1Zxv10 B860av2.1 Chinamobile Firmware
Jun 17, 2026
Dec 28, 2018
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnera...Show more
ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.Show less
1Cisco
1Adaptive Security Appliance Software
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using t...Show more
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.Show less
1Apache
1Nifi
Nov 21, 2024
Dec 19, 2018
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, re...Show more
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication, same subnet access, and injecting malicious code into an unprotected (plaintext HTTP) website which the targeted user later visits, but the possible damage warranted a Severe severity level. Mitigation: The fix to apply Cross-Origin Resource Sharing (CORS) policy request filtering was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Dec 14, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.
1Dell
3Idrac7 Firmware
Idrac8 FirmwareIdrac9 Firmware
Nov 21, 2024
Dec 13, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with...Show more
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to gain administrator access.Show less
1Pivotal Software
1Cloud Foundry Uaa Release
Nov 21, 2024
Dec 13, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authen...Show more
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.Show less
1Microfocus
1Edirectory
Nov 21, 2024
Dec 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
3Canonical
LinuxRedhat
10Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+7 more
Nov 21, 2024
Dec 12, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user ha...Show more
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.Show less
1Sap
1Business Application Software Integrated Solution
Nov 21, 2024
Dec 11, 2018
N/A· v4
8.0 HIGH· v3
6.5 MEDIUM· v2
Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Dec 7, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute...Show more
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.Show less
1Dell
1Openmanage Network Manager
Nov 21, 2024
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.
1Qnap
1Qts
Nov 21, 2024
Nov 28, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.
1Huawei
2Mate 9 Pro Firmware
Nova 2 Plus Firmware
Jun 17, 2026
Nov 27, 2018
N/A· v4
4.6 MEDIUM· v3
3.6 LOW· v2
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone...Show more
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations. Successful exploit could allow the attacker bypass the FRP protection.Show less
1Terra Master
1Terramaster Operating System
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.
1Buffalo
1Ts5600d1206 Firmware
Nov 21, 2024
Nov 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
Nov 16, 2018
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has...Show more
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.Show less
1Inova Software
1Inova Partner
Nov 21, 2024
Nov 16, 2018
N/A· v4
6.4 MEDIUM· v3
3.5 LOW· v2
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference.
1Inova Software
1Inova Partner
Nov 21, 2024
Nov 16, 2018
N/A· v4
6.4 MEDIUM· v3
3.5 LOW· v2
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions.