The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,098 vulnerabilities with CWE-863
CVE-2022-39214
CRITICAL
Combodo iTop < 2.7.8 - Authenticated Account Takeover via Username Knowledge
CVSS 9.6
CVE-2022-4315
MEDIUM
GitLab DAST Analyzer 2.0-3.0.54 - Incorrect Authorization via Custom Request Headers
CVSS 5.0
CVE-2022-46704
MEDIUM
macOS <13.1, <11.7.2, <12.6.2 - Info Disclosure
CVSS 5.5
CVE-2022-34397
MEDIUM
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp <= 10.0.0.5 - Incorrect Authorization
CVSS 6.9
CVE-2022-45544
HIGH
SCHLIX CMS 2.2.7-2 - Authenticated Arbitrary File Upload via tristao Parameter
CVSS 8.8
CVE-2022-47002
CRITICAL
Masa CMS <7.4 - Auth Bypass
CVSS 9.8
CVE-2022-45172
CRITICAL
LIVEBOX Collaboration vDesk < 018 - Unauthenticated Broken Access Control via Email Validation Endpoint
CVSS 9.8
CVE-2022-45435
MEDIUM
SailPoint IdentityIQ < 8.0 - Incorrect Authorization via Identity Forwarding Configuration
CVSS 6.8
CVE-2022-23739
CRITICAL
GitHub Enterprise Server < 3.7.1 - Incorrect Authorization in GraphQL API
CVSS 9.8
CVE-2022-45353
MEDIUM
Betheme <= 26.6.1 - Broken Access Control
CVSS 4.3
CVE-2022-2155
MEDIUM
Lumada APM 6.0.0.0-6.4.0.0 - Incorrect Authorization in User Asset Group Role
CVSS 5.7
CVE-2022-4167
MEDIUM
GitLab 13.11.0-15.5.6, 15.6.0-15.6.3, 15.7.0-15.7.1 - Incorrect Authorization in Group Access Token Revocation
CVSS 5.3
CVE-2022-46258
MEDIUM
GitHub Enterprise Server <3.7 - Auth Bypass
CVSS 6.5
CVE-2022-43438
HIGH
easy_test 17l18s-22i26 - Authenticated Incorrect Authorization
CVSS 8.8
CVE-2022-23553
HIGH
Alpine < 1.10.4 - URL Access Filter Bypass
CVSS 7.5
CVE-2022-45891
CRITICAL
Planet eStream < 6.72.10.07 - Unauthenticated Incorrect Authorization via Upload2.ashx and View.aspx
CVSS 9.1
CVE-2022-38475
MEDIUM
Firefox < 104.0 - Incorrect Authorization via Zero-Length JavaScript Array
CVSS 6.5
CVE-2022-22754
MEDIUM
Firefox < 97.0 and Firefox ESR < 91.6 - Incorrect Authorization via Extension Auto-Update
CVSS 6.5
CVE-2022-3188
MEDIUM
Dataprobe iBoot-PDU Firmware < 1.42.06162022 - Unauthenticated Information Disclosure via History File Download
CVSS 5.3
CVE-2022-23551
MEDIUM
Azure AD Pod Identity < 1.8.13 - Improper Restriction of Security Token Assignment via Backslash Bypass
CVSS 5.3
CVE-2022-43872
MEDIUM
IBM Financial Transaction Manager <3.2.4 - Info Disclosure
CVSS 5.3
CVE-2022-46076
HIGH
D-Link DIR-869 DIR869Ax_FW102B15 - Auth Bypass
CVSS 7.5
CVE-2022-23488
MEDIUM
BigBlueButton < 2.4-rc-6 - Unauthorized Webcam Stream Access via Lock Setting Bypass
CVSS 6.5
CVE-2022-23490
MEDIUM
BigBlueButton < 2.4.0 - Unauthorized Poll Response Exposure via Current-Poll Collection
CVSS 4.3
CVE-2022-42351
MEDIUM
Adobe Experience Manager < 6.5.15.0 and Cloud Service < 2022.10.0 - Incorrect Authorization
CVSS 4.3
Details
Vulnerabilities
3,098
Exploit Likelihood
High