CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,109 vulnerabilities with CWE-863
CVE-2016-20002 CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
CVE-2016-20001 CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
CVE-2016-6591 HIGH
Symantec Norton App Lock <1.0.3.186 - Auth Bypass
CVSS 7.1
CVE-2016-6353 MEDIUM
Cloudera Search <5.7.0 - Info Disclosure
CVSS 6.5
CVE-2016-4572 HIGH
Cloudera CDH - Incorrect Authorization in Impala REVOKE ALL ON SERVER Command
CVSS 8.8
CVE-2016-3131 MEDIUM
Cloudera CDH < 5.6.1 - Authorization Bypass via Direct Internal API Calls
CVSS 6.5
CVE-2016-10996 MEDIUM
OptinMonster < 1.1.4.6 - Unauthenticated Incorrect Authorization via Nonce Leak
CVSS 5.3
CVE-2016-9575 MEDIUM
FreeIPA 4.2.x, 4.3.x < 4.3.3, 4.4.x < 4.4.3 - Authenticated Certificate Profile Modification via certprofile-mod Command
CVSS 6.3
CVE-2016-6797 HIGH
Apache Tomcat 6.0.0-6.0.45, 7.0.0-7.0.70, 8.0.0.RC1-8.0.36, 8.5.0-8.5.4, 9.0.0.M1-9.0.0.M9 - Incorrect Authorization
CVSS 7.5
CVE-2016-4178 MEDIUM
Adobe Flash Player <18.0.0.366,19.x-22.x - Auth Bypass
CVSS 4.3
CVE-2016-4514 HIGH
Moxa PT-7728 3.4 build 15081113 - Authenticated Configuration Change via Local Proxy
CVSS 7.7
CVE-2015-10033 LOW
merlinsboard < 2015-03-19 - Improper Authorization in Grade Handler
CVSS 3.5
CVE-2015-1780 MEDIUM
oVirt Engine - Incorrect Authorization via Storage Domain Attachment
CVSS 6.5
CVE-2015-4106
QEMU < 2.3.1 - Incorrect Authorization in PCI Config Space
CVE-2014-7914 HIGH
Android < 5.1 - Incorrect Authorization via Bluetooth Pairing Bypass
CVSS 8.1
CVE-2014-0169 MEDIUM
JBoss Enterprise Application Platform 6 - Incorrect Authorization via Shared Security Domain Cache
CVSS 6.5
CVE-2014-8109
Apache HTTP Server 2.3.x and 2.4.x <= 2.4.10 - Incorrect Authorization via mod_lua Module
CVE-2014-3520
OpenStack Keystone < 2013.2.4 - Authenticated Incorrect Authorization via V2 API Trust Token Request
CVE-2013-4228 MEDIUM
Organic Groups 7.x-2.x < 7.x-2.3 - Authenticated Private Group Access Bypass
CVSS 4.3
CVE-2013-2673 MEDIUM
Brother MFC-9970CDW <1.10 - Auth Bypass
CVSS 6.8
CVE-2013-2198 CRITICAL
Login Security 6.x-1.0-6.x-1.2 and 7.x-1.x - Incorrect Authorization via Crafted Username
CVSS 9.8
CVE-2013-1350 CRITICAL
Veraxsystems Network Management System - Incorrect Authorization
CVSS 9.1
CVE-2013-2574 HIGH
FOSCAM IP Camera FI8620 - Info Disclosure
CVSS 7.5
CVE-2013-4862 HIGH
MiCasaVerde VeraLite <1.5.408 - Privilege Escalation
CVSS 8.1
CVE-2013-4985 HIGH
Vivotek IP7160 IP7361 IP8332 Firmware - Unauthenticated RTSP Authentication Bypass
CVSS 7.5
Details
Vulnerabilities 3,109
Exploit Likelihood High