CWE-863
3,308 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-...Show more |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Jan 8, 2019 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windo...Show more |
1Zte 1Zxv10 B860av2.1 Chinamobile Firmware Jun 17, 2026 Dec 28, 2018 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnera...Show more |
1Cisco 1Adaptive Security Appliance Software Nov 21, 2024 Dec 24, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using t...Show more |
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, re...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files. |
1Dell 3Idrac7 Firmware Idrac8 FirmwareIdrac9 FirmwareNov 21, 2024 Dec 13, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with...Show more |
1Pivotal Software 1Cloud Foundry Uaa Release Nov 21, 2024 Dec 13, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authen...Show more |
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 |
3Canonical LinuxRedhat10Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+7 moreNov 21, 2024 Dec 12, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user ha...Show more |
1Sap 1Business Application Software Integrated Solution Nov 21, 2024 Dec 11, 2018 N/A· v4 8.0 HIGH· v3 6.5 MEDIUM· v2 Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform. |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Dec 7, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute...Show more |
1Dell 1Openmanage Network Manager Nov 21, 2024 Nov 30, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file. |
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS. |
1Huawei 2Mate 9 Pro Firmware Nova 2 Plus FirmwareJun 17, 2026 Nov 27, 2018 N/A· v4 4.6 MEDIUM· v3 3.6 LOW· v2 There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone...Show more |
1Terra Master 1Terramaster Operating System Nov 21, 2024 Nov 27, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions. |
1Buffalo 1Ts5600d1206 Firmware Nov 21, 2024 Nov 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Nov 16, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has...Show more |
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference. |
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions. |