The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,108 vulnerabilities with CWE-863
CVE-2018-6316
HIGH
Ivanti Endpoint Security < 8.5 Update 1 - Authenticated Application Whitelisting Bypass in Lockdown Mode
CVSS 7.5
CVE-2018-0110
HIGH
Cisco WebEx Meetings Server - Authenticated Remote Support Account Access Bypass
CVSS 8.1
CVE-2018-0096
MEDIUM
Cisco Prime Infrastructure - Authenticated Privilege Escalation via RBAC Bypass
CVSS 5.9
CVE-2018-2361
HIGH
SAP Solution Manager 7.20 - Incorrect Authorization in SAP_BPO_CONFIG Role
CVSS 8.8
CVE-2018-0803
MEDIUM
Microsoft Edge - Cross-Domain Information Disclosure and Injection via Policy Enforcement Flaw
CVSS 4.2
CVE-2017-9453
CRITICAL
BMC Server Automation <8.9.01 - Auth Bypass
CVSS 9.0
CVE-2017-20066
MEDIUM
Adminer Login <1.4.4 - Info Disclosure
CVSS 5.3
CVE-2017-16778
MEDIUM
Fermax Outdoor Panel - Privilege Escalation
CVSS 4.6
CVE-2017-8276
HIGH
Qualcomm Snapdragon Firmware - Incorrect Authorization in TrustZone Fuse
CVSS 7.8
CVE-2017-17708
MEDIUM
Pleasant Password Server < 7.8.3 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2017-2632
MEDIUM
CloudForms Management Engine < 5.7.1.3 - Privilege Escalation via Role Validation Logic Error
CVSS 4.9
CVE-2017-7470
MEDIUM
Spacewalk-channel - Privilege Escalation
CVSS 6.5
CVE-2017-3183
HIGH
Sage XRT Treasury 3 - Authenticated Authorization Bypass via USER_CODE Manipulation
CVSS 8.8
CVE-2017-2673
MEDIUM
OpenStack Keystone >=9.0.0 - Authenticated Incorrect Authorization in Federation Configurations
CVSS 6.8
CVE-2017-16773
MEDIUM
Synology Universal Search <1.0.5-0135 - Auth Bypass
CVSS 6.5
CVE-2017-15695
HIGH
Apache Geode 1.0.0-1.4.0 - Remote Code Execution via Internal Function Invocation
CVSS 8.8
CVE-2017-2611
MEDIUM
Jenkins <2.44, 2.32.2 - Privilege Escalation
CVSS 4.3
CVE-2017-1700
MEDIUM
IBM Rational Collaborative Lifecycle Management 5.0-6.0.4 DoS via Resource Intensive Scenarios
CVSS 6.5
CVE-2017-12196
MEDIUM
undertow <1.4.18.SP1-2.0.2.Final - SSRF
CVSS 4.8
CVE-2017-2599
MEDIUM
Jenkins < 2.44 and < 2.32.2 - Incorrect Authorization via Item Overwrite
CVSS 5.4
CVE-2017-1766
MEDIUM
IBM Business Process Manager 8.6 - Incorrect Authorization
CVSS 4.3
CVE-2017-0920
MEDIUM
GitLab <10.1.6, 10.2.6, 10.3.4 - Auth Bypass
CVSS 4.3
CVE-2017-0927
MEDIUM
GitLab 8.16.0-9.5.9 - Unauthenticated Improper Authorization in Deployment Keys
CVSS 6.5
CVE-2017-0926
HIGH
GitLab 8.8.0-9.5.9 - Unauthenticated Unauthorized User Login via OAuth Sign-In
CVSS 8.8
CVE-2017-0922
HIGH
GitLab 9.1.0-9.5.10 - Authorization Bypass in Projects::BoardsController
CVSS 7.5
Details
Vulnerabilities
3,108
Exploit Likelihood
High