CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 8 of 31
- CVE-2022-31668HIGHCVSS 7.4EG 7.42024-11-14
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the a…
- CVE-2022-31669MEDIUMCVSS 6.4EG 6.42024-11-14
Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have ac…
- CVE-2022-31670HIGHCVSS 7.7EG 7.72024-11-14
Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access …
- CVE-2022-31671HIGHCVSS 7.4EG 7.42024-11-14
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, m…
- CVE-2022-3187MEDIUMCVSS 5.3EG 5.32022-12-21
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. …
- CVE-2022-32169MEDIUMCVSS 4.3EG 4.32022-09-28
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.
- CVE-2022-32170MEDIUMCVSS 4.3EG 4.32022-09-28
The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId…
- CVE-2022-3229CRITICALCVSS 9.8EG 9.82023-02-06
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol,…
- CVE-2022-32838MEDIUMCVSS 5.5EG 5.52022-08-24
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6. An app may be able to read arbitrary files.
- CVE-2022-33702MEDIUMCVSS 6.2EG 6.22022-07-12
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
- CVE-2022-33705LOWCVSS 3.3EG 3.32022-07-12
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.
- CVE-2022-33712MEDIUMCVSS 5.3EG 5.32022-07-12
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.
- CVE-2022-33713HIGHCVSS 7.5EG 7.52022-07-12
Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.
- CVE-2022-33722MEDIUMCVSS 4.0EG 4.02022-08-05
Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.
- CVE-2022-34256HIGHCVSS 7.5EG 7.52022-08-16
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability…
- CVE-2022-34363HIGHCVSS 7.5EG 7.52026-05-26
Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp
- CVE-2022-34405HIGHCVSS 7.3EG 7.32023-01-26
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to th…
- CVE-2022-34434MEDIUMCVSS 6.7EG 6.72022-10-11
Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to either the vApp or containerized versions of Cloud Mobility…
- CVE-2022-34446HIGHCVSS 8.8EG 8.82023-02-11
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive infor…
- CVE-2022-36090HIGHCVSS 8.1EG 8.12022-09-08
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are missing a check for inactive (not yet activated or disabled) users in XWiki, including the …
- CVE-2022-36110HIGHCVSS 8.8EG 8.82022-09-09
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, t…
- CVE-2022-36453HIGHCVSS 8.8EG 8.82022-10-25
A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the auth…
- CVE-2022-36454MEDIUMCVSS 6.5EG 6.52022-10-25
A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authentica…
- CVE-2022-3683HIGHCVSS 7.7EG 7.72023-03-28
A vulnerability exists in the SDM600 API web services authorization validation implementation. An attacker who successfully exploits the vulnerability could read data directly from a data store that is not restricted, or insufficiently pr…
- CVE-2022-36837MEDIUMCVSS 6.2EG 6.22022-08-05
Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.
- CVE-2022-36838MEDIUMCVSS 4.0EG 4.62022-08-05
Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.
- CVE-2022-36848MEDIUMCVSS 5.1EG 5.52022-09-09
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
- CVE-2022-3685HIGHCVSS 7.5EG 7.52023-03-28
A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. An attacker who successfully exploits this vulnerability can escalate privileges. This issue affe…
- CVE-2022-36852LOWCVSS 1.9EG 3.32022-09-09
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.
- CVE-2022-36857LOWCVSS 1.9EG 2.42022-09-09
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
- CVE-2022-3686CRITICALCVSS 4.8EG 9.12023-03-28
A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the application unresponsive. This issue affects: All SDM600 ve…
- CVE-2022-36870MEDIUMCVSS 5.0EG 6.52022-09-09
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- CVE-2022-36871MEDIUMCVSS 5.0EG 6.52022-09-09
Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- CVE-2022-36872MEDIUMCVSS 5.0EG 6.52022-09-09
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- CVE-2022-36876LOWCVSS 1.8EG 2.42022-09-09
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.
- CVE-2022-3740MEDIUMCVSS 6.5EG 6.52023-01-26
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to …
- CVE-2022-3748CRITICALCVSS 9.8EG 9.82023-04-14
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
- CVE-2022-3787HIGHCVSS 7.8EG 7.82023-03-29
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain socket…
- CVE-2022-38375CRITICALCVSS 9.1EG 9.82023-02-16
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST…
- CVE-2022-3876MEDIUMCVSS 4.3EG 6.52022-12-19
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of…
- CVE-2022-39322CRITICALCVSS 9.1EG 9.12022-10-25
@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if co…
- CVE-2022-39329LOWCVSS 3.5EG 3.52022-10-27
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be …
- CVE-2022-39340MEDIUMCVSS 5.3EG 5.32022-10-25
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.…
- CVE-2022-39341MEDIUMCVSS 5.9EG 5.92022-10-25
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) defined on tupleset relations in their authorization model are vu…
- CVE-2022-39342MEDIUMCVSS 5.9EG 5.92022-10-25
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users whose model has a relation defined as a tupleset (the right hand side of a ‘from’ sta…
- CVE-2022-39356HIGHCVSS 8.9EG 8.92022-11-02
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All us…
- CVE-2022-39862CRITICALCVSS 5.3EG 9.82022-10-07
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.
- CVE-2022-39873MEDIUMCVSS 4.3EG 4.62022-10-07
Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.
- CVE-2022-39879MEDIUMCVSS 5.9EG 5.92022-11-09
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
- CVE-2022-39883HIGHCVSS 4.0EG 7.82022-11-09
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →