CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2020-24264 CRITICAL
Portainer < 1.24.1 - Incorrect Authorization Leading to Remote Code Execution via Bind Mount Bypass
CVSS 9.8
CVE-2020-25240 HIGH
SINEMA Remote Connect Server < 3.0 - Unauthenticated Incorrect Authorization via URL Guessing
CVSS 8.8
CVE-2020-25239 HIGH
SINEMA Remote Connect Server < 3.0 - Unauthorized UMC Authorization Server Modification via Special URLs
CVSS 8.8
CVE-2020-35682 HIGH
ManageEngine ServiceDesk Plus < 11134 - Authentication Bypass via SAML Login
CVSS 8.8
CVE-2020-29020 CRITICAL
Secomea SiteManager < 9.4.620527004 - Improper Access Control in Web Service
CVSS 9.1
CVE-2020-12668 MEDIUM
Jinjava < 2.5.4 - Arbitrary Class Access and Arbitrary File Disclosure via Java Method Calls
CVSS 6.5
CVE-2020-8806 HIGH
Electric Coin Company Zcashd <2.1.1-1 - DoS
CVSS 7.5
CVE-2020-27873 MEDIUM
NETGEAR AC2100 R7450 < 1.2.0.76 - Unauthenticated Sensitive Information Disclosure via SOAP API
CVSS 6.5
CVE-2020-29605 MEDIUM
MantisBT < 2.24.4 - Authenticated Private Issue Summary Exposure via bug_actiongroup_page.php
CVSS 4.3
CVE-2020-1725 MEDIUM
Keycloak < 13.0.0 - Incorrect Authorization
CVSS 5.4
CVE-2020-9492 HIGH
Apache Hadoop 2.0.0-2.10.0 and 3.0.0-alpha1-3.2.1 - Incorrect Authorization via WebHDFS SPNEGO Header
CVSS 8.8
CVE-2020-4873 MEDIUM
IBM Planning Analytics 2.0 - Sensitive Information Exposure via Overly Permissive CORS Policy
CVSS 5.3
CVE-2020-35948 CRITICAL
XCloner Backup and Restore 4.2.1-4.2.12 - Arbitrary File Write & RCE via xcloner_restore.php
CVSS 9.9
CVE-2020-26029 MEDIUM
Zammad < 3.4.1 - Incorrect Authorization via X-On-Behalf-Of Header
CVSS 6.5
CVE-2020-26028 MEDIUM
Zammad < 3.4.1 - Incorrect Authorization for Admin Users
CVSS 4.9
CVE-2020-24674 HIGH
S+ Operations/S+ Historian - DoS/Code Injection
CVSS 8.8
CVE-2020-4794 MEDIUM
IBM Automation Workstream Services 19.0.3, 20.0.1-20.0.2 - Authenticated Information Disclosure and Denial of Service
CVSS 5.4
CVE-2020-0481 LOW
Android 11 - Unauthenticated Permissions Bypass via Broadcast Intent
CVSS 3.3
CVE-2020-0479 HIGH
Android 11 - Unauthenticated Permissions Bypass in DocumentsProvider
CVSS 7.8
CVE-2020-0473 MEDIUM
Android - Local Privilege Escalation via Bluetooth File Transfer
CVSS 4.6
CVE-2020-8919 LOW
Gerrit 2.15.0-2.15.20 - Unauthenticated Information Disclosure via Branch REST API
CVSS 3.5
CVE-2020-29454 MEDIUM
Umbraco CMS < 8.9.1 - Incorrect Authorization in LogViewer Endpoint
CVSS 4.3
CVE-2020-26250 MEDIUM
OAuthenticator <0.12.2 - Info Disclosure
CVSS 6.3
CVE-2020-29374 LOW
Linux kernel <5.7.3 - Memory Corruption
CVSS 3.6
CVE-2020-15248 MEDIUM
October CMS <1.0.470 - Privilege Escalation
CVSS 4.0
Details
Vulnerabilities 3,104
Exploit Likelihood High