CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,108 vulnerabilities with CWE-863
CVE-2017-17668 HIGH
NCR S1 Dispenser Controller Firmware < 0x0156 - Unauthenticated Firmware Downgrade via Memory Write Mechanism
CVSS 7.5
CVE-2017-17323 MEDIUM
Huawei iBMC <V200R002C10-V200R002C30 - Info Disclosure
CVSS 4.3
CVE-2017-18095 MEDIUM
Atlassian Crucible < 4.5.1 - Unauthenticated Improper Authorization in SnippetRPCServiceImpl
CVSS 5.3
CVE-2017-1233 MEDIUM
IBM BigFix Remote Control - Unauthorized File Replacement and Privilege Escalation
CVSS 6.7
CVE-2017-16858 MEDIUM
Atlassian Crowd <3.1.2 - Auth Bypass
CVSS 6.8
CVE-2017-15091 HIGH
PowerDNS Authoritative 3.0-3.4.11 and 4.0-4.0.4 - Authenticated Unauthorized State Change via API
CVSS 7.1
CVE-2017-12118 HIGH
cpp-ethereum - Improper Authorization
CVSS 8.1
CVE-2017-12116 HIGH
cpp-ethereum - Unauthenticated Authorization Bypass via miner_setGasPrice API
CVSS 8.1
CVE-2017-12113 HIGH
cpp-ethereum - Incorrect Authorization via admin_nodeInfo API
CVSS 8.1
CVE-2017-12117 HIGH
cpp-ethereum - Unauthenticated Authorization Bypass via JSON-RPC miner_start API
CVSS 8.1
CVE-2017-12115 HIGH
cpp-ethereum - Incorrect Authorization via miner_setEtherbase API
CVSS 8.1
CVE-2017-12114 MEDIUM
cpp-ethereum - Unauthenticated Authorization Bypass via admin_peers API
CVSS 6.8
CVE-2017-12112 HIGH
cpp-ethereum - Unauthenticated Authorization Bypass via admin_addPeer API
CVSS 8.1
CVE-2017-12197 MEDIUM
libpam4j <= 1.8 - Authentication Bypass via Disabled Account Validation
CVSS 6.5
CVE-2017-16743 CRITICAL
PHOENIX CONTACT FL SWITCH - Auth Bypass
CVSS 9.8
CVE-2017-4946 HIGH
VMware V4H & V4PA <6.5.1 - Privilege Escalation
CVSS 7.8
CVE-2017-17067 CRITICAL
Splunk 6.3.0-6.3.11 - Incorrect Authorization via SAML Authentication Bypass
CVSS 9.8
CVE-2017-1628 MEDIUM
IBM Business Process Manager 8.6.0.0 - Privilege Escalation
CVSS 6.5
CVE-2017-0910 HIGH
Zulip Server <1.7.1 - Privilege Escalation
CVSS 8.8
CVE-2017-8216 MEDIUM
Huawei P10 Lite Firmware < Warsaw-AL00C00B180 - Unauthenticated Information Disclosure
CVSS 5.5
CVE-2017-8196 MEDIUM
FusionSphere V100R006C00SPC102(NFV) - Authenticated Incorrect Authorization
CVSS 4.2
CVE-2017-8192 HIGH
FusionSphere OpenStack V100R006C00 - Incorrect Authorization
CVSS 7.8
CVE-2017-3891 CRITICAL
BlackBerry QNX SDP <6.6.0 - Privilege Escalation
CVSS 9.6
CVE-2017-12261 HIGH
Cisco Identity Services Engine Privilege Escalation via Command Injection
CVSS 7.8
CVE-2017-5060 MEDIUM
Google Chrome <58.0.3029 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 3,108
Exploit Likelihood High