CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,108 vulnerabilities with CWE-863
CVE-2018-0337 HIGH
Cisco NX-OS - Authenticated Command Injection via File System Input Validation Bypass
CVSS 7.8
CVE-2018-8927 MEDIUM
Synology Calendar < 2.1.2-0511 - Authenticated Arbitrary Event Creation via cal_id or original_cal_id Parameter
CVSS 5.4
CVE-2018-0338 HIGH
Cisco Unified Computing System - Authenticated Command Injection via CLI
CVSS 7.8
CVE-2018-1000197 HIGH
Jenkins Black Duck Hub Plugin <3.0.3 - Auth Bypass
CVSS 8.1
CVE-2018-11142 MEDIUM
Quest KACE System Management Appliance 8.0.318 - Unauthenticated Incorrect Authorization via Host Header Bypass
CVSS 5.5
CVE-2018-1000155 CRITICAL
OpenFlow 1.0 onwards - Denial of Service and Improper Authorization via DPID Trust in Handshake
CVSS 9.8
CVE-2018-1463 MEDIUM
IBM SAN Volume Controller - Privilege Escalation
CVSS 6.5
CVE-2018-1462 HIGH
IBM SAN Volume Controller - Privilege Escalation
CVSS 7.6
CVE-2018-1278 MEDIUM
Pivotal Application Service 1.12.0-1.12.21 - Incorrect Authorization in Apps Manager
CVSS 6.5
CVE-2018-1258 HIGH
Spring Security - Incorrect Authorization Bypass via Method Security
CVSS 8.8
CVE-2018-0278 MEDIUM
Cisco Secure Firewall Management Center - Unauthenticated Sensitive Information Exposure via WebSocket
CVSS 6.5
CVE-2018-5520 MEDIUM
F5 BIG-IP <13.1.0.5 - Privilege Escalation
CVSS 4.4
CVE-2018-10212 MEDIUM
Vaultize Enterprise File Sharing <17.05.31 - Privilege Escalation
CVSS 5.4
CVE-2018-0269 MEDIUM
Cisco Digital Network Architecture Center - Unauthenticated Sensitive Information Exposure via CORS Misconfiguration
CVSS 4.3
CVE-2018-7245 CRITICAL
Schneider Electric 66074 MGE Network Management Card Transverse - Unauthenticated Parameter Modification via Web Server
CVSS 9.1
CVE-2018-1000152 MEDIUM
Jenkins vSphere Plugin <2.16 - Privilege Escalation
CVSS 6.3
CVE-2018-1057 HIGH
Canonical Ubuntu Linux < 4.5.16 - Incorrect Authorization
CVSS 8.8
CVE-2018-1000114 MEDIUM
Jenkins Promoted Builds Plugin <2.31.1 - Privilege Escalation
CVSS 4.3
CVE-2018-1000112 MEDIUM
Jenkins Mercurial Plugin <2.2 - Info Disclosure
CVSS 5.3
CVE-2018-1000111 MEDIUM
Jenkins Subversion Plugin <2.10.2 - Auth Bypass
CVSS 5.3
CVE-2018-1000110 MEDIUM
Jenkins Git Plugin <3.7.0 - Auth Bypass
CVSS 5.3
CVE-2018-1000109 MEDIUM
Jenkins Google Play Android Publisher Plugin <1.6 - Auth Bypass
CVSS 4.3
CVE-2018-1000107 MEDIUM
Jenkins Job and Node Ownership Plugin <0.11.0 - Privilege Escalation
CVSS 6.5
CVE-2018-1000106 MEDIUM
Jenkins Gerrit Trigger Plugin <2.27.4 - Privilege Escalation
CVSS 5.4
CVE-2018-1000105 MEDIUM
Jenkins Gerrit Trigger Plugin <2.27.4 - Auth Bypass
CVSS 4.3
Details
Vulnerabilities 3,108
Exploit Likelihood High