CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,064 vulnerabilities with CWE-863
CVE-2025-21562 MEDIUM
Oracle PeopleSoft Enterprise CC Common Application Objects 9.2 - Unauthorized Data Access via Run Control Management
CVSS 4.3
CVE-2025-21561 MEDIUM
Oracle PeopleSoft Enterprise SCM Purchasing 9.2 - Incorrect Authorization
CVSS 5.4
CVE-2025-21560 MEDIUM
Oracle Agile PLM Framework 9.3.6 - Unauthorized Data Access via SDK
CVSS 6.5
CVE-2025-21558 MEDIUM
Oracle Primavera P6 EPPM 20.12.1.0-21.12.20.0 Incorrect Authorization via Web Access
CVSS 5.4
CVE-2025-21557 MEDIUM
Oracle Application Express 23.2 and 24.1 - Incorrect Authorization via HTTP
CVSS 5.4
CVE-2025-21556 CRITICAL
Oracle Agile PLM Framework 9.3.6 - Incorrect Authorization via Agile Integration Services
CVSS 9.9
CVE-2025-21555 MEDIUM
MySQL Server < 8.0.40 - Authenticated Denial of Service and Unauthorized Data Manipulation in InnoDB
CVSS 5.5
CVE-2025-21554 MEDIUM
Oracle Communications Order and Service Management 7.4.0, 7.4.1, 7.5.0 - Unauthenticated Unauthorized Data Access
CVSS 5.3
CVE-2025-21553 MEDIUM
Oracle Java VM 19.3-19.25, 21.3-21.16, 23.4-23.6 - Unauthorized Data Access via Oracle Net
CVSS 4.2
CVE-2025-21546 LOW
MySQL Server < 8.0.40, 8.4.3, 9.1.0 - Authenticated Incorrect Authorization in Privilege Management
CVSS 3.8
CVE-2025-21540 MEDIUM
MySQL Server < 8.0.40, <= 8.4.3, 9.1.0 - Authenticated Incorrect Authorization in Privilege Handling
CVSS 5.4
CVE-2025-21539 MEDIUM
Oracle PeopleSoft Enterprise FIN eSettlements 9.2 - Incorrect Authorization via HTTP
CVSS 5.4
CVE-2025-21537 MEDIUM
PeopleSoft Enterprise FIN Cash Management 9.2 - Incorrect Authorization
CVSS 5.4
CVE-2025-21533 MEDIUM
Oracle VM VirtualBox < 7.0.24 and < 7.1.6 - Unauthorized Data Access via Core Component
CVSS 5.5
CVE-2025-21519 MEDIUM
MySQL Server < 8.0.40, <= 8.4.3, 9.1.0 - Authenticated Denial of Service in Privilege Handling
CVSS 4.4
CVE-2025-21517 MEDIUM
Oracle JD Edwards EnterpriseOne Tools < 9.2.9.0 - Unauthorized Data Manipulation via Web Runtime SEC
CVSS 4.3
CVE-2025-21516 HIGH
Oracle E-Business Suite 12.2.5-12.2.13 - Authenticated Incorrect Authorization in Service Requests
CVSS 8.1
CVE-2025-21506 HIGH
Oracle E-Business Suite 12.2.3-12.2.13 - Authenticated Incorrect Authorization in Technology Foundation
CVSS 8.1
CVE-2025-21502 MEDIUM
Oracle GraalVM - Incorrect Authorization
CVSS 4.8
CVE-2025-24460 MEDIUM
JetBrains TeamCity < 2024.12.1 - Unauthenticated Project Name Disclosure via Agent Pool
CVSS 4.3
CVE-2025-0580 MEDIUM
Shiprocket Module 3 on OpenCart - Auth Bypass
CVSS 5.6
CVE-2025-21403 MEDIUM
Microsoft On-Premises Data Gateway < 3000.246 - Information Disclosure
CVSS 6.4
CVE-2025-22449 LOW
Mattermost 9.11.0-9.11.5 - Incorrect Authorization via Team Public Setting
CVSS 3.8
CVE-2025-0237 MEDIUM
Firefox <134, Thunderbird <128.6 - Privilege Escalation
CVSS 5.4
CVE-2024-47272 LOW
Synology Surveillance Station - Incorrect Authorization
CVSS 2.7
Details
Vulnerabilities 3,064
Exploit Likelihood High