CWE-285— Improper Authorization
1,227 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 7 of 25
- CVE-2022-29236MEDIUMCVSS 4.3EG 4.32022-06-02
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently…
- CVE-2022-29490HIGHCVSS 8.5EG 8.82022-09-12
Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issu…
- CVE-2022-29913MEDIUMCVSS 6.5EG 6.52022-12-22
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.
- CVE-2022-30670HIGHCVSS 8.8EG 6.52022-06-16
RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrat…
- CVE-2022-30717MEDIUMCVSS 4.0EG 7.52022-06-07
Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.
- CVE-2022-30722MEDIUMCVSS 6.2EG 9.82022-06-07
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.
- CVE-2022-30730MEDIUMCVSS 4.6EG 4.62022-06-07
Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.
- CVE-2022-30746HIGHCVSS 7.5EG 7.52022-06-07
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.
- CVE-2022-30757MEDIUMCVSS 4.0EG 3.32022-07-12
Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.
- CVE-2022-31025LOWCVSS 2.6EG 2.62022-06-07
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_a…
- CVE-2022-31167HIGHCVSS 7.1EG 7.12022-09-07
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to documen…
- CVE-2022-31168MEDIUMCVSS 5.4EG 5.42022-07-22
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. Th…
- CVE-2022-31247CRITICALCVSS 9.1EG 9.12022-09-07
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and …
- CVE-2022-31609HIGHCVSS 7.8EG 7.82022-08-05
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and con…
- CVE-2022-31666HIGHCVSS 7.7EG 7.72024-11-14
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook policies configured in other projects.
- CVE-2022-31667MEDIUMCVSS 6.4EG 6.42024-11-14
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. By sending a request that attempts to update a robot account, and specifying a …
- CVE-2022-31668HIGHCVSS 7.4EG 7.42024-11-14
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the a…
- CVE-2022-31669MEDIUMCVSS 6.4EG 6.42024-11-14
Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have ac…
- CVE-2022-31670HIGHCVSS 7.7EG 7.72024-11-14
Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access …
- CVE-2022-31671HIGHCVSS 7.4EG 7.42024-11-14
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, m…
- CVE-2022-3187MEDIUMCVSS 5.3EG 5.32022-12-21
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. …
- CVE-2022-32169MEDIUMCVSS 4.3EG 4.32022-09-28
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.
- CVE-2022-32170MEDIUMCVSS 4.3EG 4.32022-09-28
The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId…
- CVE-2022-3229CRITICALCVSS 9.8EG 9.82023-02-06
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol,…
- CVE-2022-32838MEDIUMCVSS 5.5EG 5.52022-08-24
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6. An app may be able to read arbitrary files.
- CVE-2022-33702MEDIUMCVSS 6.2EG 5.52022-07-12
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
- CVE-2022-33705LOWCVSS 3.3EG 3.32022-07-12
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.
- CVE-2022-33712MEDIUMCVSS 5.3EG 5.32022-07-12
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.
- CVE-2022-33713HIGHCVSS 7.5EG 7.52022-07-12
Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.
- CVE-2022-33722MEDIUMCVSS 4.0EG 3.32022-08-05
Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.
- CVE-2022-34256HIGHCVSS 7.5EG 7.52022-08-16
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability…
- CVE-2022-34363MEDIUMCVSS 6.5EG 6.52026-05-26
Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp
- CVE-2022-34405HIGHCVSS 7.3EG 7.32023-01-26
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to th…
- CVE-2022-34434MEDIUMCVSS 6.7EG 6.72022-10-11
Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to either the vApp or containerized versions of Cloud Mobility…
- CVE-2022-34446HIGHCVSS 8.8EG 8.12023-02-11
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive infor…
- CVE-2022-36090HIGHCVSS 8.1EG 8.12022-09-08
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are missing a check for inactive (not yet activated or disabled) users in XWiki, including the …
- CVE-2022-36110HIGHCVSS 8.8EG 8.82022-09-09
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, t…
- CVE-2022-36453HIGHCVSS 8.8EG 8.82022-10-25
A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the auth…
- CVE-2022-36454MEDIUMCVSS 6.5EG 6.52022-10-25
A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authentica…
- CVE-2022-3683HIGHCVSS 7.7EG 7.52023-03-28
A vulnerability exists in the SDM600 API web services authorization validation implementation. An attacker who successfully exploits the vulnerability could read data directly from a data store that is not restricted, or insufficiently pr…
- CVE-2022-36837MEDIUMCVSS 6.2EG 5.52022-08-05
Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.
- CVE-2022-36838MEDIUMCVSS 4.0EG 4.62022-08-05
Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.
- CVE-2022-36848MEDIUMCVSS 5.1EG 5.52022-09-09
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
- CVE-2022-3685HIGHCVSS 7.5EG 7.22023-03-28
A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. An attacker who successfully exploits this vulnerability can escalate privileges. This issue affe…
- CVE-2022-36852LOWCVSS 1.9EG 3.32022-09-09
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.
- CVE-2022-36857LOWCVSS 1.9EG 2.42022-09-09
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
- CVE-2022-3686MEDIUMCVSS 4.8EG 9.12023-03-28
A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the application unresponsive. This issue affects: All SDM600 ve…
- CVE-2022-36870MEDIUMCVSS 5.0EG 6.52022-09-09
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- CVE-2022-36871MEDIUMCVSS 5.0EG 6.52022-09-09
Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- CVE-2022-36872MEDIUMCVSS 5.0EG 6.52022-09-09
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →