CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2020-15246 HIGH
October CMS <1.0.469 - Info Disclosure
CVSS 7.5
CVE-2020-28053 MEDIUM
HashiCorp Consul 1.2.0-1.8.5 - Incorrect Authorization for Connect CA Private Key
CVSS 6.5
CVE-2020-28211 HIGH
EcoStruxure Control Expert - Incorrect Authorization via Debugger Memory Overwrite
CVSS 7.8
CVE-2020-25701 MEDIUM
Moodle 3.5.0-3.5.14, 3.7.0-3.7.8, 3.8.0-3.8.5, 3.9.0-3.9.2 - Improper Access Control via Upload Course Tool
CVSS 5.3
CVE-2020-25699 HIGH
Moodle 3.5.0-3.5.14, 3.7.0-3.7.8, 3.8.0-3.8.5, 3.9.0-3.9.2 - Incorrect Authorization in Course Restore
CVSS 7.5
CVE-2020-8278 MEDIUM
Nextcloud Social <0.3.1 - Info Disclosure
CVSS 5.3
CVE-2020-26223 HIGH
Spree 3.7.0-3.7.12 - Incorrect Authorization via API v2 Order Status Endpoint
CVSS 7.7
CVE-2020-11209 MEDIUM
Qualcomm Sd820 Firmware - Incorrect Authorization
CVSS 5.5
CVE-2020-17049 MEDIUM
Windows Server 2012, 2016, 2019 and Samba 4.1.0-4.13.12 - Security Feature Bypass in Kerberos Constrained Delegation
CVSS 6.6
CVE-2020-25655 MEDIUM
Red Hat Advanced Cluster Management for Kubernetes - Incorrect Authorization in ManagedClusterView API
CVSS 5.7
CVE-2020-24401 MEDIUM
Magento <2.4.0-2.3.5p1 - Auth Bypass
CVSS 6.5
CVE-2020-3600 HIGH
Cisco SD-WAN Software - Privilege Escalation
CVSS 7.8
CVE-2020-3592 MEDIUM
Cisco SD-WAN vManage < 20.1.12 - Authenticated Authorization Bypass via Crafted HTTP Requests
CVSS 6.5
CVE-2020-26506 MEDIUM
Marmind 4.1.141.0 - Authorization Bypass
CVSS 4.3
CVE-2020-15278 HIGH
Red Discord Bot <3.4.1 - Privilege Escalation
CVSS 7.7
CVE-2020-3852 MEDIUM
Safari < 13.0.5 - Incorrect Authorization via URL Scheme Handling
CVSS 5.3
CVE-2020-3578 MEDIUM
Cisco ASA/Firepower Threat Defense WebVPN Portal Unauthenticated Access Rule Bypass
CVSS 5.3
CVE-2020-27609 MEDIUM
BigBlueButton <2.2.28 - Info Disclosure
CVSS 5.3
CVE-2020-6362 MEDIUM
SAP Banking Services 500 - Privilege Escalation
CVSS 6.5
CVE-2020-16904 MEDIUM
Azure Functions - Unauthenticated Incorrect Authorization
CVSS 5.3
CVE-2020-12503 HIGH
Pepperl+Fuchs P+F Comtrol - Authenticated Command Injection
CVSS 7.2
CVE-2020-27156 CRITICAL
Veritas APTARE < 10.5 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2020-13957 CRITICAL
Apache Solr 6.6.0-6.6.6 7.0.0-7.7.3 8.0.0-8.6.2 - Unauthenticated ConfigSet Upload Bypass
CVSS 9.8
CVE-2020-15251 HIGH
Sopel <1.0.3 - Privilege Escalation
CVSS 7.7
CVE-2020-3467 HIGH
Cisco Identity Services Engine - Authenticated Incorrect Authorization via Web-Based Management Interface
CVSS 7.7
Details
Vulnerabilities 3,104
Exploit Likelihood High