The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2020-12875
MEDIUM
Veritas APTARE <10.4 - Info Disclosure
CVSS 6.3
CVE-2020-1998
MEDIUM
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via SAML Username Sharing
CVSS 5.4
CVE-2020-8151
HIGH
Active Resource <v5.1.1 - Info Disclosure
CVSS 7.5
CVE-2020-12691
HIGH
OpenStack Keystone <16.0.0 - Privilege Escalation
CVSS 8.8
CVE-2020-7921
MEDIUM
MongoDB Server <4.2.3, <4.0.15, <4.3.3, <3.6.18 - Auth Bypass
CVSS 4.6
CVE-2020-4446
MEDIUM
IBM Business Process Manager 8.0-8.6 and Business Automation Workflow 18.0-19.0 - Incorrect Authorization
CVSS 4.3
CVE-2020-2188
MEDIUM
Jenkins Amazon EC2 Plugin < 1.50.1 - Unauthenticated Credential ID Enumeration via Form Methods
CVSS 4.3
CVE-2020-5343
HIGH
Dell OS Recovery Image for Windows 10 < 2019-12-20 - Unauthorized Access via Insecure Permissions
CVSS 7.3
CVE-2020-5333
MEDIUM
RSA Archer < 6.7.0.3 - Authenticated Authorization Bypass in REST API
CVSS 4.3
CVE-2020-12477
HIGH
TeamPass 2.1.27.36 - IP Whitelist Bypass via X-Forwarded-For Header
CVSS 7.5
CVE-2020-10786
HIGH
Vesta Control Panel <0.9.8-26 - RCE
CVSS 8.8
CVE-2020-11753
HIGH
Sonatype Nexus Repository Manager 3.21.1 and 3.22.0 - Incorrect Authorization
CVSS 8.8
CVE-2020-5293
MEDIUM
PrestaShop 1.7.0.0-1.7.6.5 - Improper Access Control on Product Page
CVSS 6.5
CVE-2020-5288
MEDIUM
PrestaShop 1.7.0.0-1.7.6.5 - Improper Access Control on Product Attributes Page
CVSS 4.1
CVE-2020-5287
MEDIUM
PrestaShop 1.5.5.0-1.7.6.5 - Improper Access Control in Customer Search
CVSS 4.1
CVE-2020-5279
MEDIUM
PrestaShop 1.5.0.0-1.7.6.5 - Improper Access Control in Legacy Controllers
CVSS 4.1
CVE-2020-0981
HIGH
Windows 10 and Windows Server 2016 - Security Feature Bypass via Token Handling
CVSS 8.8
CVE-2020-6214
MEDIUM
SAP S/4HANA 100 - Privilege Escalation
CVSS 4.7
CVE-2020-11707
HIGH
ProVide < 13.1 - Sandbox Escape via Symlink or Junction
CVSS 8.8
CVE-2020-11628
MEDIUM
EJBCA < 6.15.2.6 and 7.x < 7.3.1.2 - Protocol Access Control Bypass via URI Manipulation
CVSS 5.3
CVE-2020-8142
MEDIUM
Revive Adserver <5.0.5 - Auth Bypass
CVSS 6.8
CVE-2020-5275
HIGH
Symfony security-http < 4.4.7 - Improper Authorization via Access Control Rule Bypass
CVSS 7.6
CVE-2020-10510
HIGH
Sunnet eHRD - Incorrect Authorization via Specific URL
CVSS 8.1
CVE-2020-1796
MEDIUM
HUAWEI Mate 20 and Mate 30 Pro Firmware - Incorrect Authorization
CVSS 6.6
CVE-2020-10239
HIGH
Joomla! 3.7.0-3.9.15 - Incorrect Access Control in com_fields SQL Fieldtype
CVSS 8.8
Details
Vulnerabilities
3,104
Exploit Likelihood
High