CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2019-19200 HIGH
REDDOXX MailDepot 2032-2.2.1242 - Privilege Escalation
CVSS 8.8
CVE-2019-20801 MEDIUM
Readdle Documents < 6.9.7 - Unauthenticated Data Access via Cross-Origin WebSocket
CVSS 5.3
CVE-2019-11361 HIGH
Zoho ManageEngine Remote Access Plus <10.0.258 - Privilege Escalation
CVSS 8.8
CVE-2019-13001 MEDIUM
GitLab 11.9.0-12.0.2 - Unauthenticated Snippet Comment Authorization Bypass
CVSS 4.3
CVE-2019-4745 MEDIUM
IBM Maximo Asset Mgmt <7.6.1.0 - Info Disclosure
CVSS 4.3
CVE-2019-5474 MEDIUM
GitLab 11.8.0-11.11.5 - Improper Access Control via Merge Request Approval Rules
CVSS 6.5
CVE-2019-17190 HIGH
Avast Secure Browser 76.0.1659.101 - Local Privilege Escalation via Update.ini Hard Link
CVSS 7.8
CVE-2019-17014 HIGH
Firefox < 71.0 - Cross-Origin Information Leak via Dragged Image
CVSS 7.4
CVE-2019-14843 HIGH
Red Hat Single Sign-On - Authentication Bypass
CVSS 8.8
CVE-2019-6855 HIGH
EcoStruxure Control Expert <14.1 - Auth Bypass
CVSS 7.3
CVE-2019-20213 HIGH
D-Link DIR-859 Firmware < 1.07b03_beta - Unauthenticated Information Disclosure via AUTHORIZED_GROUP Parameter
CVSS 7.5
CVE-2019-12837 MEDIUM
accesuniversitat.gencat.cat 1.7.5 - Unauthenticated Personal Information Exposure via Java API
CVSS 4.3
CVE-2019-4343 MEDIUM
IBM Cognos Analytics 11.0-11.1 - SSRF
CVSS 6.5
CVE-2019-19681 HIGH
Pandora FMS 7.x - Authenticated Remote Code Execution via Alert System Command Injection
CVSS 8.8
CVE-2019-19984 MEDIUM
Email Subscribers & Newsletters < 4.2.3 - Incorrect Authorization
CVSS 6.3
CVE-2019-11294 MEDIUM
Cloud Foundry CAPI 1.88.0 - Unauthorized Exposure of Sensitive Service Broker Information
CVSS 4.3
CVE-2019-8512 MEDIUM
iPhone OS < 12.2 - Unauthenticated Remote Device Wipe via Enterprise Administrator Authorization
CVSS 5.7
CVE-2019-0384 HIGH
SAP Treasury and Risk Management - Incorrect Authorization
CVSS 8.8
CVE-2019-0383 HIGH
SAP Treasury and Risk Management - Authenticated Privilege Escalation via Missing Authorization Check
CVSS 8.8
CVE-2019-7192 CRITICAL KEV
QNAP Photo Station - Info Disclosure
CVSS 9.8
CVE-2019-19597 HIGH
D-Link DAP-1860 <v1.04b03 Beta - RCE
CVSS 8.8
CVE-2019-19520 HIGH
OpenBSD 6.6 - Privilege Escalation via LIBGL_DRIVERS_PATH Environment Variable
CVSS 7.8
CVE-2019-5879 MEDIUM
Google Chrome < 77.0.3865.75 - Insufficient Policy Enforcement in Extensions
CVSS 6.5
CVE-2019-5864 MEDIUM
Chrome < 76.0.3809.87 - Content Security Policy Bypass via Malicious Extension
CVSS 4.3
CVE-2019-13716 MEDIUM
Google Chrome < 78.0.3904.70 - Incorrect Authorization via Service Worker Policy Bypass
CVSS 4.3
Details
Vulnerabilities 3,104
Exploit Likelihood High