CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,088 vulnerabilities with CWE-863
CVE-2023-46125 MEDIUM
Fides < 2.22.1 - Unauthorized Exposure of Sensitive Configuration via API Endpoint
CVSS 6.5
CVE-2023-43961 HIGH
Dromara SaToken <1.3.50RC - Auth Bypass
CVSS 8.8
CVE-2023-43508 MEDIUM
ClearPass Policy Manager - Privilege Escalation
CVSS 6.3
CVE-2023-34051 CRITICAL
VMware Aria Operations for Logs - RCE
CVSS 9.8
CVE-2023-22067 MEDIUM
Oracle Java SE <8u381-21.3.7 - Unauthorized Update
CVSS 5.3
CVE-2023-43119 CRITICAL
Extreme Networks Switch Engine <32.5.1.5 - Privilege Escalation
CVSS 9.8
CVE-2023-29484 MEDIUM
Terminalfour < 8.3.16 - Incorrect Authorization via LDAP Misconfiguration
CVSS 6.5
CVE-2023-38218 HIGH
Adobe Commerce <=2.4.7-beta1, <=2.4.6-p2, <=2.4.5-p4, <=2.4.4-p5 - Authenticated Info Exposure & Privilege Escalation
CVSS 8.8
CVE-2023-40829 HIGH
Tencent Enterprise Wechat Privatization <2.6.930000 - Info Disclosure
CVSS 7.5
CVE-2023-41882 MEDIUM
vantage6 < 4.0.0 - Improper Access Control in Task Collection Endpoint
CVSS 5.4
CVE-2023-35653 MEDIUM
Google Android - Incorrect Authorization
CVSS 4.4
CVE-2023-28635 MEDIUM
vantage6 < 4.0.0 - Incorrect Authorization via Integer Resource Name
CVSS 5.4
CVE-2023-5521 CRITICAL
kernelsu < 0.6.9 - Incorrect Authorization
CVSS 9.8
CVE-2023-36556 HIGH
FortiMail 6.0.0-6.0.11, 7.0.0-7.0.5, 7.2.0-7.2.2 - Authenticated Incorrect Authorization via Crafted HTTP Requests
CVSS 8.8
CVE-2023-44860 HIGH
NETIS SYSTEMS N3Mv2 1.0.1.865 - Denial of Service via Authorization Component
CVSS 7.5
CVE-2023-1832 MEDIUM
Candlepin < 4.3.7-3 - Improper Access Control
CVSS 6.8
CVE-2023-4997 HIGH
ProIntegra Uptime DC < 2.0.0.33940 - Authenticated Privilege Escalation via Password Change
CVSS 8.8
CVE-2023-5106 HIGH
GitLab EE <16.2.8-16.4.1 - Privilege Escalation
CVSS 8.2
CVE-2023-5195 MEDIUM
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in Team Soft Delete
CVSS 6.5
CVE-2023-5194 LOW
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in User Demotion
CVSS 2.7
CVE-2023-5193 MEDIUM
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in Direct Message Post Retrieval
CVSS 4.9
CVE-2023-5159 LOW
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in Bot Management
CVSS 3.8
CVE-2023-5198 MEDIUM
GitLab <16.2.7, <16.3.5, <16.4.1 - Info Disclosure
CVSS 4.3
CVE-2023-4532 MEDIUM
GitLab <16.2.8-16.4.1 - Info Disclosure
CVSS 4.3
CVE-2023-3979 LOW
GitLab 10.6-16.2.7, 16.3-16.3.4, 16.4 - Incorrect Authorization in Merge Request Source Branch
CVSS 3.1
Details
Vulnerabilities 3,088
Exploit Likelihood High