CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,108 vulnerabilities with CWE-863
CVE-2017-10379 MEDIUM
MySQL < 5.5.57, 5.6.37, 5.7.19 - Authenticated Unauthorized Data Access via Client Programs
CVSS 6.5
CVE-2017-9653 CRITICAL
OSIsoft PI Integrator <2016 R2 - Privilege Escalation
CVSS 9.8
CVE-2017-8633 HIGH
Windows Error Reporting - Elevation of Privilege via Incorrect Authorization
CVSS 7.5
CVE-2017-9855 CRITICAL
SMA Solar Technology - Privilege Escalation
CVSS 9.8
CVE-2017-6672 HIGH
Cisco ASR 5000 Series Software - Unauthenticated Access Control List Bypass
CVSS 7.5
CVE-2017-7512 CRITICAL
Red Hat 3scale <2.0.0 - Auth Bypass
CVSS 9.8
CVE-2017-10805 HIGH
Odoo 8.0, 9.0, 10.0 - Authenticated OAuth Session Hijacking via Incorrect Access Control
CVSS 8.8
CVE-2017-8907 HIGH
Atlassian Bamboo <5.15.7-6.0.1 - RCE
CVSS 8.8
CVE-2017-9378 MEDIUM
BigTree CMS <4.2.18 - Info Disclosure
CVSS 6.5
CVE-2017-2306 HIGH
Juniper Networks Junos Space <16.1R1 - Code Injection
CVSS 8.8
CVE-2017-2305 HIGH
Juniper Networks Junos Space <16.1R1 - Privilege Escalation
CVSS 8.8
CVE-2017-7505 HIGH
Foreman <1.5 - Privilege Escalation
CVSS 8.8
CVE-2017-4915 HIGH
VMware Workstation Pro/Player - Privilege Escalation
CVSS 7.8
CVE-2017-0894 MEDIUM
Nextcloud Server <11.0.3 - Info Disclosure
CVSS 4.3
CVE-2017-3817 MEDIUM
Cisco UCS Director <6.0 - Info Disclosure
CVSS 4.3
CVE-2017-0881 MEDIUM
Zulip <1.4.3 - Privilege Escalation
CVSS 4.3
CVE-2017-5618 HIGH
GNU screen < 4.5.1 - Unauthenticated Arbitrary File Write via Logfile Permissions
CVSS 7.8
CVE-2017-6377 HIGH
Drupal 8.2.x < 8.2.7 - Incorrect Authorization in Private File Editor
CVSS 7.5
CVE-2017-6816 MEDIUM
WordPress < 4.7.3 - Unintended File Deletion via Plugin Deletion Functionality
CVSS 4.9
CVE-2017-6590 MEDIUM
Ubuntu Linux - Unauthenticated Local File Access and Command Execution via Network Manager Applet
CVSS 6.3
CVE-2017-3801 HIGH
Cisco UCS Director <6.0.1 - Privilege Escalation
CVSS 8.8
CVE-2016-20075 HIGH
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
CVSS 8.8
CVE-2016-20005 CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
CVE-2016-20004 CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
CVE-2016-20002 CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
Details
Vulnerabilities 3,108
Exploit Likelihood High