CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2021-27099 MEDIUM
SPIRE < 0.8.5, 0.9.4, 0.10.2, 0.11.3, 0.12.1 - Incorrect Authorization via AWS IID Node Attestor Path Normalization
CVSS 6.8
CVE-2021-26964 HIGH
Aruba AirWave < 8.2.12.0 - Authenticated Privilege Escalation via Web Management Interface
CVSS 7.1
CVE-2021-21725 MEDIUM
ZTE ZXHN H196Q V9.1.0C2 - Authenticated Directory Traversal and Information Disclosure
CVSS 5.7
CVE-2021-26027 MEDIUM
Joomla! 3.0.0-3.9.24 - Incorrect Authorization in Article Category Change
CVSS 5.3
CVE-2021-27225 MEDIUM
Dataiku DSS <8.0.6 - Info Disclosure
CVSS 5.4
CVE-2021-26563 HIGH
Synology DiskStation Manager < 6.2.4-25553 - Incorrect Authorization
CVSS 8.2
CVE-2021-20229 MEDIUM
PostgreSQL < 13.2 - Unauthorized Column Access via SELECT Privilege Escalation
CVSS 4.3
CVE-2021-22113 MEDIUM
Spring Cloud Netflix Zuul < 2.2.6 - Incorrect Authorization via Specially Constructed URLs
CVSS 5.3
CVE-2021-27509 HIGH
Visualware MyConnection Server <11.0b-5382 - Info Disclosure
CVSS 7.5
CVE-2021-21318 MEDIUM
Opencast < 9.2 - Incorrect Authorization via Series Access Control Overwrite
CVSS 5.4
CVE-2021-26753 CRITICAL
NeDi 1.9C - Authenticated PHP Code Injection via System Files Endpoint
CVSS 9.9
CVE-2021-20188 HIGH
podman < 1.7.0 - Incorrect Authorization via Privileged Container File Permissions
CVSS 7.0
CVE-2021-27177 CRITICAL
FiberHome HG6245D Firmware < rp2613 - Unauthenticated Telnet Authentication Bypass via Decoded String
CVSS 9.8
CVE-2021-25777 MEDIUM
JetBrains TeamCity < 2020.2.1 - Incorrect Authorization during Token Removal
CVSS 5.3
CVE-2021-25774 MEDIUM
JetBrains TeamCity < 2020.2.1 - Incorrect Authorization
CVSS 4.3
CVE-2021-21286 HIGH
AVideo Platform <10.2 - Auth Bypass
CVSS 7.7
CVE-2021-21276 CRITICAL
polr < 2.3.0 - Unauthenticated Admin Account Creation via Setup Finish Endpoint
CVSS 9.3
CVE-2021-3337 HIGH
Hide-Thread-Content Plugin through 2021-01-27 for MyBB - Unauthenticated Information Disclosure via Reply or Quote
CVSS 7.5
CVE-2021-26026 HIGH
ACDSee Professional 2021 14.0 1721 - User Mode Write Access Violation via Crafted BMP Image
CVSS 7.8
CVE-2021-26025 HIGH
ACDSee Professional 2021 14.0 1721 - User Mode Write Access Violation via Crafted BMP Image
CVSS 7.8
CVE-2021-1305 HIGH
Cisco SD-WAN vManage Software - Authenticated Authorization Bypass and Information Disclosure
CVSS 8.8
CVE-2021-1270 MEDIUM
Cisco Data Center Network Manager < 11.5(1) - Authenticated Incorrect Authorization
CVSS 6.3
CVE-2021-1269 MEDIUM
Cisco Data Center Network Manager < 11.5(1) - Authenticated Incorrect Authorization
CVSS 6.3
CVE-2021-21013 HIGH
Magento <2.4.1-2.3.6 - Info Disclosure
CVSS 8.1
CVE-2021-1144 HIGH
Cisco Connected Mobile Experiences - Authenticated Password Modification via Incorrect Authorization
CVSS 8.8
Details
Vulnerabilities 3,104
Exploit Likelihood High