CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 14 of 83
- CVE-2020-5194MEDIUMCVSS 5.4EG 5.42020-01-14
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_downloa…
- CVE-2020-5197MEDIUMCVSS 4.3EG 4.32020-01-13
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.
- CVE-2020-5239HIGHCVSS 8.7EG 8.72020-02-13
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrusted users are most impacted. The master a…
- CVE-2020-5240HIGHCVSS 7.6EG 7.62020-03-13
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they…
- CVE-2020-5242HIGHCVSS 7.7EG 7.72020-02-20
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Starting with version 2…
- CVE-2020-5251HIGHCVSS 7.7EG 7.72020-03-04
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.
- CVE-2020-5275HIGHCVSS 7.6EG 7.62020-03-30
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preven…
- CVE-2020-5279MEDIUMCVSS 4.1EG 4.12020-04-20
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/internatio…
- CVE-2020-5287MEDIUMCVSS 4.1EG 4.12020-04-20
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.
- CVE-2020-5288MEDIUMCVSS 4.1EG 4.12020-04-20
"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.
- CVE-2020-5293MEDIUMCVSS 6.5EG 6.52020-04-20
In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in 1.7.6.5.
- CVE-2020-5318HIGHCVSS 7.5EG 7.52020-02-06
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The non-RAN HTTP and WebDAV file-serving com…
- CVE-2020-5333MEDIUMCVSS 4.3EG 4.32020-05-04
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.
- CVE-2020-5343HIGHCVSS 7.3EG 7.32020-05-04
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vul…
- CVE-2020-5372HIGHCVSS 8.6EG 8.62020-07-06
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which a…
- CVE-2020-5418MEDIUMCVSS 4.3EG 4.32020-09-03
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).
- CVE-2020-5582MEDIUMCVSS 4.3EG 4.32020-06-30
Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for the file attached to Report via unspecified vectors.
- CVE-2020-5598HIGHCVSS 7.5EG 7.52020-07-07
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper access control vulnerability, which may which may …
- CVE-2020-5855MEDIUMCVSS 4.3EG 4.32020-02-06
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.
- CVE-2020-5863HIGHCVSS 8.6EG 8.62020-03-27
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cann…
- CVE-2020-6214MEDIUMCVSS 4.7EG 4.72020-04-14
SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an…
- CVE-2020-6307MEDIUMCVSS 4.3EG 4.32020-01-14
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.
- CVE-2020-6311MEDIUMCVSS 6.5EG 6.52020-09-09
Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorizat…
- CVE-2020-6320HIGHCVSS 8.1EG 8.12020-09-09
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related…
- CVE-2020-6362MEDIUMCVSS 6.5EG 6.52020-10-20
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to privilege escalati…
- CVE-2020-6380HIGHCVSS 8.8EG 8.82020-02-11
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.
- CVE-2020-6528MEDIUMCVSS 4.3EG 4.32020-07-22
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2020-6641MEDIUMCVSS 4.3EG 4.32021-06-02
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.
- CVE-2020-6752LOWCVSS 3.8EG 3.82020-06-17
In OMERO before 5.6.1, group owners can access members' data in other groups.
- CVE-2020-7038HIGHCVSS 7.5EG 7.52021-04-28
A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected versions of Manage…
- CVE-2020-7251MEDIUMCVSS 5.0EG 5.02020-02-14
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from o…
- CVE-2020-7300MEDIUMCVSS 4.6EG 6.32020-08-12
Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HT…
- CVE-2020-7499MEDIUMCVSS 6.5EG 6.52020-06-16
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized change…
- CVE-2020-7583HIGHCVSS 7.8EG 7.82020-08-14
A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The application does not properly validate the users' privileges when executing some operations, whic…
- CVE-2020-7692HIGHCVSS 7.4EG 7.42020-07-09
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initia…
- CVE-2020-7921MEDIUMCVSS 4.6EG 5.32020-05-06
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This…
- CVE-2020-7955MEDIUMCVSS 5.3EG 5.32020-01-31
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
- CVE-2020-8086CRITICALCVSS 9.8EG 9.82020-01-28
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches th…
- CVE-2020-8119MEDIUMCVSS 4.3EG 4.32020-02-04
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
- CVE-2020-8142MEDIUMCVSS 6.8EG 6.82020-04-03
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in orde…
- CVE-2020-8151HIGHCVSS 7.5EG 7.52020-05-12
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
- CVE-2020-8212CRITICALCVSS 9.8EG 9.82020-08-17
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.
- CVE-2020-8278MEDIUMCVSS 5.3EG 5.32020-11-19
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
- CVE-2020-8334MEDIUMCVSS 6.1EG 6.12020-06-09
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.
- CVE-2020-8463HIGHCVSS 7.5EG 7.52020-12-17
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.
- CVE-2020-8495HIGHCVSS 7.5EG 7.52020-01-30
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within…
- CVE-2020-8576MEDIUMCVSS 5.4EG 5.42020-09-02
Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or disclosure of sensitive information.
- CVE-2020-8581MEDIUMCVSS 6.5EG 6.52021-01-19
Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.
- CVE-2020-8806HIGHCVSS 7.5EG 7.52021-02-05
Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid chain could be incorrectly rejected because timestamp requirements on block headers were not properly enforced.
- CVE-2020-8919LOWCVSS 3.5EG 3.52020-12-10
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other …
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →