CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,098 vulnerabilities with CWE-863
CVE-2022-39214 CRITICAL
Combodo iTop < 2.7.8 - Authenticated Account Takeover via Username Knowledge
CVSS 9.6
CVE-2022-4315 MEDIUM
GitLab DAST Analyzer 2.0-3.0.54 - Incorrect Authorization via Custom Request Headers
CVSS 5.0
CVE-2022-46704 MEDIUM
macOS <13.1, <11.7.2, <12.6.2 - Info Disclosure
CVSS 5.5
CVE-2022-34397 MEDIUM
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp <= 10.0.0.5 - Incorrect Authorization
CVSS 6.9
CVE-2022-45544 HIGH
SCHLIX CMS 2.2.7-2 - Authenticated Arbitrary File Upload via tristao Parameter
CVSS 8.8
CVE-2022-47002 CRITICAL
Masa CMS <7.4 - Auth Bypass
CVSS 9.8
CVE-2022-45172 CRITICAL
LIVEBOX Collaboration vDesk < 018 - Unauthenticated Broken Access Control via Email Validation Endpoint
CVSS 9.8
CVE-2022-45435 MEDIUM
SailPoint IdentityIQ < 8.0 - Incorrect Authorization via Identity Forwarding Configuration
CVSS 6.8
CVE-2022-23739 CRITICAL
GitHub Enterprise Server < 3.7.1 - Incorrect Authorization in GraphQL API
CVSS 9.8
CVE-2022-45353 MEDIUM
Betheme <= 26.6.1 - Broken Access Control
CVSS 4.3
CVE-2022-2155 MEDIUM
Lumada APM 6.0.0.0-6.4.0.0 - Incorrect Authorization in User Asset Group Role
CVSS 5.7
CVE-2022-4167 MEDIUM
GitLab 13.11.0-15.5.6, 15.6.0-15.6.3, 15.7.0-15.7.1 - Incorrect Authorization in Group Access Token Revocation
CVSS 5.3
CVE-2022-46258 MEDIUM
GitHub Enterprise Server <3.7 - Auth Bypass
CVSS 6.5
CVE-2022-43438 HIGH
easy_test 17l18s-22i26 - Authenticated Incorrect Authorization
CVSS 8.8
CVE-2022-23553 HIGH
Alpine < 1.10.4 - URL Access Filter Bypass
CVSS 7.5
CVE-2022-45891 CRITICAL
Planet eStream < 6.72.10.07 - Unauthenticated Incorrect Authorization via Upload2.ashx and View.aspx
CVSS 9.1
CVE-2022-38475 MEDIUM
Firefox < 104.0 - Incorrect Authorization via Zero-Length JavaScript Array
CVSS 6.5
CVE-2022-22754 MEDIUM
Firefox < 97.0 and Firefox ESR < 91.6 - Incorrect Authorization via Extension Auto-Update
CVSS 6.5
CVE-2022-3188 MEDIUM
Dataprobe iBoot-PDU Firmware < 1.42.06162022 - Unauthenticated Information Disclosure via History File Download
CVSS 5.3
CVE-2022-23551 MEDIUM
Azure AD Pod Identity < 1.8.13 - Improper Restriction of Security Token Assignment via Backslash Bypass
CVSS 5.3
CVE-2022-43872 MEDIUM
IBM Financial Transaction Manager <3.2.4 - Info Disclosure
CVSS 5.3
CVE-2022-46076 HIGH
D-Link DIR-869 DIR869Ax_FW102B15 - Auth Bypass
CVSS 7.5
CVE-2022-23488 MEDIUM
BigBlueButton < 2.4-rc-6 - Unauthorized Webcam Stream Access via Lock Setting Bypass
CVSS 6.5
CVE-2022-23490 MEDIUM
BigBlueButton < 2.4.0 - Unauthorized Poll Response Exposure via Current-Poll Collection
CVSS 4.3
CVE-2022-42351 MEDIUM
Adobe Experience Manager < 6.5.15.0 and Cloud Service < 2022.10.0 - Incorrect Authorization
CVSS 4.3
Details
Vulnerabilities 3,098
Exploit Likelihood High