CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2020-3522 MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated Authorization Bypass via Crafted URL
CVSS 6.3
CVE-2020-19005 MEDIUM
zrlog 2.1.0 - Incorrect Authorization for Database Backup Download
CVSS 5.7
CVE-2020-16241 MEDIUM
Philips SureSigns VS4 Firmware < a.07.107 - Improper Access Control
CVSS 6.3
CVE-2020-9712 MEDIUM
Adobe Acrobat and Reader DC - Security Feature Bypass via Incorrect Authorization
CVSS 5.5
CVE-2020-3472 MEDIUM
Cisco Webex Meetings - Info Disclosure
CVSS 5.0
CVE-2020-3413 MEDIUM
Cisco Webex Meetings - Privilege Escalation
CVSS 4.3
CVE-2020-3412 MEDIUM
Cisco Webex Meetings - Privilege Escalation
CVSS 4.3
CVE-2020-8212 CRITICAL
Citrix XenMobile <10.12 - Privilege Escalation
CVSS 9.8
CVE-2020-7583 HIGH
Siemens Automation License Manager 5.x and 6.x < 6.0.8 - Improper Authorization
CVSS 7.8
CVE-2020-7300 MEDIUM
McAfee Data Loss Prevention < 11.3.28 - Authenticated Configuration Change via HTTP Post Messages
CVSS 4.6
CVE-2020-2233 MEDIUM
Jenkins Pipeline Maven Integration Plugin <3.8.2 - Info Disclosure
CVSS 6.5
CVE-2020-17448 HIGH
Telegram Desktop <2.1.13 - Info Disclosure
CVSS 7.8
CVE-2020-12780 HIGH
Combodo iTop < 2.7.1 - Sensitive Information Exposure via Security Misconfiguration
CVSS 7.5
CVE-2020-3386 HIGH
Cisco Data Center Network Manager < 11.4(1) - Authenticated Improper Authorization via REST API
CVSS 8.8
CVE-2020-3374 CRITICAL
Cisco SD-WAN vManage Software - Auth Bypass
CVSS 9.9
CVE-2020-14486 MEDIUM
OpenClinic GA 5.09.02 and 5.89.05b - Improper Authorization via Redirect Bypass
CVSS 6.3
CVE-2020-15120 MEDIUM
I hate money <4.1.5 - Privilege Escalation
CVSS 4.9
CVE-2020-15126 MEDIUM
Parser-Server <4.3.0 - Privilege Escalation
CVSS 6.5
CVE-2020-15110 MEDIUM
jupyterhub-kubespawner <0.12 - Privilege Escalation
CVSS 6.8
CVE-2020-3150 MEDIUM
Cisco Small Business RV110W/RV215W - Info Disclosure
CVSS 5.9
CVE-2020-3140 CRITICAL
Cisco Prime License Manager - Privilege Escalation
CVSS 9.8
CVE-2020-2228 HIGH
Jenkins Gitlab Auth Plugin <1.5 - Privilege Escalation
CVSS 8.8
CVE-2020-7692 HIGH
Google OAuth Client Library for Java < 1.31.0 - Incorrect Authorization via Missing PKCE Implementation
CVSS 7.4
CVE-2020-15513 MEDIUM
mittwald/typo3_forum < 1.2.1 - Incorrect Access Control
CVSS 5.3
CVE-2020-5372 HIGH
Dell EMC PowerStore < 1.0.1.0.5.002 - Unauthenticated Denial of Service via Exposed Test Interface Ports
CVSS 8.6
Details
Vulnerabilities 3,104
Exploit Likelihood High