CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,505 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 7 of 31
- CVE-2022-0406MEDIUMCVSS 4.3EG 4.32022-04-03
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
- CVE-2022-0587MEDIUMCVSS 6.5EG 6.52022-02-15
Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
- CVE-2022-0726MEDIUMCVSS 5.4EG 5.42022-02-23
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
- CVE-2022-0756MEDIUMCVSS 6.5EG 6.52022-03-07
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- CVE-2022-0821MEDIUMCVSS 6.5EG 6.52022-03-11
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- CVE-2022-0829HIGHCVSS 8.1EG 8.12022-03-02
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
- CVE-2022-0860CRITICALCVSS 9.1EG 9.12022-03-11
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
- CVE-2022-0993CRITICALCVSS 8.1EG 9.82022-04-19
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs u…
- CVE-2022-1224MEDIUMCVSS 6.5EG 6.52022-04-04
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- CVE-2022-2019HIGHCVSS 7.3EG 7.52022-06-09
A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php?f=save of the component New User Creation. The manip…
- CVE-2022-20921HIGHCVSS 8.8EG 8.82022-08-25
A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific…
- CVE-2022-21196CRITICALCVSS 10.0EG 10.02022-02-18
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An att…
- CVE-2022-22267MEDIUMCVSS 4.0EG 4.02022-01-10
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
- CVE-2022-22268MEDIUMCVSS 6.1EG 6.12022-01-10
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
- CVE-2022-22269MEDIUMCVSS 4.0EG 4.02022-01-10
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
- CVE-2022-22272MEDIUMCVSS 4.0EG 4.02022-01-10
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission
- CVE-2022-22288HIGHCVSS 7.5EG 7.52022-01-10
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
- CVE-2022-23542HIGHCVSS 7.7EG 7.72022-12-20
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain co…
- CVE-2022-2393MEDIUMCVSS 5.7EG 5.72022-07-14
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another…
- CVE-2022-24002MEDIUMCVSS 4.0EG 5.32022-02-11
Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.
- CVE-2022-24083CRITICALCVSS 9.8EG 9.82022-07-25
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
- CVE-2022-24894MEDIUMCVSS 5.9EG 5.92023-02-03
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a …
- CVE-2022-2536HIGHCVSS 5.3EG 7.52022-12-15
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of settings on the 'tp_transl…
- CVE-2022-2595CRITICALCVSS 10.0EG 10.02022-08-01
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
- CVE-2022-26310HIGHCVSS 7.3EG 8.82022-08-01
Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could…
- CVE-2022-2661CRITICALCVSS 9.9EG 9.92022-08-16
Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests.
- CVE-2022-2675MEDIUMCVSS 6.5EG 6.52022-08-05
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be af…
- CVE-2022-26773HIGHCVSS 7.1EG 7.12022-05-26
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete files for which it does not have permission.
- CVE-2022-26857CRITICALCVSS 9.0EG 9.02022-05-26
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and…
- CVE-2022-27583CRITICALCVSS 9.1EG 9.12022-10-31
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.
- CVE-2022-28776HIGHCVSS 5.9EG 7.82022-04-11
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
- CVE-2022-2901HIGHCVSS 7.1EG 7.12022-09-06
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
- CVE-2022-29233MEDIUMCVSS 4.3EG 4.32022-06-02
BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The per…
- CVE-2022-29234MEDIUMCVSS 4.3EG 4.32022-06-02
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was chang…
- CVE-2022-29236MEDIUMCVSS 4.3EG 4.32022-06-02
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently…
- CVE-2022-29490HIGHCVSS 8.5EG 8.82022-09-12
Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issu…
- CVE-2022-29913MEDIUMCVSS 6.5EG 6.52022-12-22
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.
- CVE-2022-30670HIGHCVSS 8.8EG 8.82022-06-16
RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrat…
- CVE-2022-30717HIGHCVSS 4.0EG 7.52022-06-07
Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.
- CVE-2022-30722CRITICALCVSS 6.2EG 9.82022-06-07
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.
- CVE-2022-30730MEDIUMCVSS 4.6EG 4.62022-06-07
Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.
- CVE-2022-30746HIGHCVSS 7.5EG 7.52022-06-07
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.
- CVE-2022-30757MEDIUMCVSS 4.0EG 4.02022-07-12
Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.
- CVE-2022-31025LOWCVSS 2.6EG 2.62022-06-07
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_a…
- CVE-2022-31167HIGHCVSS 7.1EG 7.12022-09-07
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to documen…
- CVE-2022-31168MEDIUMCVSS 5.4EG 5.42022-07-22
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. Th…
- CVE-2022-31247CRITICALCVSS 9.1EG 9.12022-09-07
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and …
- CVE-2022-31609HIGHCVSS 7.8EG 7.82022-08-05
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and con…
- CVE-2022-31666HIGHCVSS 7.7EG 7.72024-11-14
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook policies configured in other projects.
- CVE-2022-31667MEDIUMCVSS 6.4EG 6.42024-11-14
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. By sending a request that attempts to update a robot account, and specifying a …
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →