CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2020-12875 MEDIUM
Veritas APTARE <10.4 - Info Disclosure
CVSS 6.3
CVE-2020-1998 MEDIUM
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via SAML Username Sharing
CVSS 5.4
CVE-2020-8151 HIGH
Active Resource <v5.1.1 - Info Disclosure
CVSS 7.5
CVE-2020-12691 HIGH
OpenStack Keystone <16.0.0 - Privilege Escalation
CVSS 8.8
CVE-2020-7921 MEDIUM
MongoDB Server <4.2.3, <4.0.15, <4.3.3, <3.6.18 - Auth Bypass
CVSS 4.6
CVE-2020-4446 MEDIUM
IBM Business Process Manager 8.0-8.6 and Business Automation Workflow 18.0-19.0 - Incorrect Authorization
CVSS 4.3
CVE-2020-2188 MEDIUM
Jenkins Amazon EC2 Plugin < 1.50.1 - Unauthenticated Credential ID Enumeration via Form Methods
CVSS 4.3
CVE-2020-5343 HIGH
Dell OS Recovery Image for Windows 10 < 2019-12-20 - Unauthorized Access via Insecure Permissions
CVSS 7.3
CVE-2020-5333 MEDIUM
RSA Archer < 6.7.0.3 - Authenticated Authorization Bypass in REST API
CVSS 4.3
CVE-2020-12477 HIGH
TeamPass 2.1.27.36 - IP Whitelist Bypass via X-Forwarded-For Header
CVSS 7.5
CVE-2020-10786 HIGH
Vesta Control Panel <0.9.8-26 - RCE
CVSS 8.8
CVE-2020-11753 HIGH
Sonatype Nexus Repository Manager 3.21.1 and 3.22.0 - Incorrect Authorization
CVSS 8.8
CVE-2020-5293 MEDIUM
PrestaShop 1.7.0.0-1.7.6.5 - Improper Access Control on Product Page
CVSS 6.5
CVE-2020-5288 MEDIUM
PrestaShop 1.7.0.0-1.7.6.5 - Improper Access Control on Product Attributes Page
CVSS 4.1
CVE-2020-5287 MEDIUM
PrestaShop 1.5.5.0-1.7.6.5 - Improper Access Control in Customer Search
CVSS 4.1
CVE-2020-5279 MEDIUM
PrestaShop 1.5.0.0-1.7.6.5 - Improper Access Control in Legacy Controllers
CVSS 4.1
CVE-2020-0981 HIGH
Windows 10 and Windows Server 2016 - Security Feature Bypass via Token Handling
CVSS 8.8
CVE-2020-6214 MEDIUM
SAP S/4HANA 100 - Privilege Escalation
CVSS 4.7
CVE-2020-11707 HIGH
ProVide < 13.1 - Sandbox Escape via Symlink or Junction
CVSS 8.8
CVE-2020-11628 MEDIUM
EJBCA < 6.15.2.6 and 7.x < 7.3.1.2 - Protocol Access Control Bypass via URI Manipulation
CVSS 5.3
CVE-2020-8142 MEDIUM
Revive Adserver <5.0.5 - Auth Bypass
CVSS 6.8
CVE-2020-5275 HIGH
Symfony security-http < 4.4.7 - Improper Authorization via Access Control Rule Bypass
CVSS 7.6
CVE-2020-10510 HIGH
Sunnet eHRD - Incorrect Authorization via Specific URL
CVSS 8.1
CVE-2020-1796 MEDIUM
HUAWEI Mate 20 and Mate 30 Pro Firmware - Incorrect Authorization
CVSS 6.6
CVE-2020-10239 HIGH
Joomla! 3.7.0-3.9.15 - Incorrect Access Control in com_fields SQL Fieldtype
CVSS 8.8
Details
Vulnerabilities 3,104
Exploit Likelihood High