CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,108 vulnerabilities with CWE-863
CVE-2018-6316 HIGH
Ivanti Endpoint Security < 8.5 Update 1 - Authenticated Application Whitelisting Bypass in Lockdown Mode
CVSS 7.5
CVE-2018-0110 HIGH
Cisco WebEx Meetings Server - Authenticated Remote Support Account Access Bypass
CVSS 8.1
CVE-2018-0096 MEDIUM
Cisco Prime Infrastructure - Authenticated Privilege Escalation via RBAC Bypass
CVSS 5.9
CVE-2018-2361 HIGH
SAP Solution Manager 7.20 - Incorrect Authorization in SAP_BPO_CONFIG Role
CVSS 8.8
CVE-2018-0803 MEDIUM
Microsoft Edge - Cross-Domain Information Disclosure and Injection via Policy Enforcement Flaw
CVSS 4.2
CVE-2017-9453 CRITICAL
BMC Server Automation <8.9.01 - Auth Bypass
CVSS 9.0
CVE-2017-20066 MEDIUM
Adminer Login <1.4.4 - Info Disclosure
CVSS 5.3
CVE-2017-16778 MEDIUM
Fermax Outdoor Panel - Privilege Escalation
CVSS 4.6
CVE-2017-8276 HIGH
Qualcomm Snapdragon Firmware - Incorrect Authorization in TrustZone Fuse
CVSS 7.8
CVE-2017-17708 MEDIUM
Pleasant Password Server < 7.8.3 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2017-2632 MEDIUM
CloudForms Management Engine < 5.7.1.3 - Privilege Escalation via Role Validation Logic Error
CVSS 4.9
CVE-2017-7470 MEDIUM
Spacewalk-channel - Privilege Escalation
CVSS 6.5
CVE-2017-3183 HIGH
Sage XRT Treasury 3 - Authenticated Authorization Bypass via USER_CODE Manipulation
CVSS 8.8
CVE-2017-2673 MEDIUM
OpenStack Keystone >=9.0.0 - Authenticated Incorrect Authorization in Federation Configurations
CVSS 6.8
CVE-2017-16773 MEDIUM
Synology Universal Search <1.0.5-0135 - Auth Bypass
CVSS 6.5
CVE-2017-15695 HIGH
Apache Geode 1.0.0-1.4.0 - Remote Code Execution via Internal Function Invocation
CVSS 8.8
CVE-2017-2611 MEDIUM
Jenkins <2.44, 2.32.2 - Privilege Escalation
CVSS 4.3
CVE-2017-1700 MEDIUM
IBM Rational Collaborative Lifecycle Management 5.0-6.0.4 DoS via Resource Intensive Scenarios
CVSS 6.5
CVE-2017-12196 MEDIUM
undertow <1.4.18.SP1-2.0.2.Final - SSRF
CVSS 4.8
CVE-2017-2599 MEDIUM
Jenkins < 2.44 and < 2.32.2 - Incorrect Authorization via Item Overwrite
CVSS 5.4
CVE-2017-1766 MEDIUM
IBM Business Process Manager 8.6 - Incorrect Authorization
CVSS 4.3
CVE-2017-0920 MEDIUM
GitLab <10.1.6, 10.2.6, 10.3.4 - Auth Bypass
CVSS 4.3
CVE-2017-0927 MEDIUM
GitLab 8.16.0-9.5.9 - Unauthenticated Improper Authorization in Deployment Keys
CVSS 6.5
CVE-2017-0926 HIGH
GitLab 8.8.0-9.5.9 - Unauthenticated Unauthorized User Login via OAuth Sign-In
CVSS 8.8
CVE-2017-0922 HIGH
GitLab 9.1.0-9.5.10 - Authorization Bypass in Projects::BoardsController
CVSS 7.5
Details
Vulnerabilities 3,108
Exploit Likelihood High