CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 21 of 83
- CVE-2021-28823HIGHCVSS 8.8EG 8.82021-03-23
The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker wi…
- CVE-2021-28824HIGHCVSS 8.8EG 8.82021-03-23
The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a lo…
- CVE-2021-28825HIGHCVSS 8.8EG 8.82021-04-14
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerabili…
- CVE-2021-28826HIGHCVSS 8.8EG 8.82021-04-14
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnera…
- CVE-2021-28911CRITICALCVSS 9.8EG 9.82021-09-09
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those info, a possible loginId can be self-calculated in a brute…
- CVE-2021-28936HIGHCVSS 7.5EG 7.52021-03-29
The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous au…
- CVE-2021-29141MEDIUMCVSS 6.5EG 6.52021-04-29
A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this secur…
- CVE-2021-29144MEDIUMCVSS 6.5EG 6.52021-04-29
A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this secur…
- CVE-2021-29158MEDIUMCVSS 4.9EG 4.92021-04-23
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
- CVE-2021-29394MEDIUMCVSS 6.5EG 6.52022-02-04
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in…
- CVE-2021-29424HIGHCVSS 7.5EG 7.52021-04-06
The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP address…
- CVE-2021-29437HIGHCVSS 8.0EG 8.02021-04-13
ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scratch user visits 3rd party site. 2. 3rd party site asks user…
- CVE-2021-29439HIGHCVSS 7.2EG 7.22021-04-13
The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.login` can install third-party plugins and their dependencies. By installing the right plugin,…
- CVE-2021-29452HIGHCVSS 8.1EG 8.12021-04-16
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were …
- CVE-2021-29628HIGHCVSS 7.5EG 7.52021-05-28
In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be disabled for the duration of the system…
- CVE-2021-29642MEDIUMCVSS 5.3EG 5.32021-03-30
GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of GitHub access tokens.
- CVE-2021-29658HIGHCVSS 8.8EG 8.82021-03-31
The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder.
- CVE-2021-29659MEDIUMCVSS 6.5EG 6.52021-05-20
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Second…
- CVE-2021-29662HIGHCVSS 7.5EG 7.52021-03-31
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP ad…
- CVE-2021-29671LOWCVSS 3.3EG 3.32021-04-09
IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled. IBM X-Force ID: 199478.
- CVE-2021-29678HIGHCVSS 8.7EG 8.72021-12-09
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.
- CVE-2021-29751MEDIUMCVSS 4.3EG 4.32021-06-28
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.
- CVE-2021-29760MEDIUMCVSS 4.3EG 4.32021-10-06
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unauthorized files through the dashboard user interface. IBM X-Force ID: 202213.
- CVE-2021-29883MEDIUMCVSS 4.3EG 4.32021-10-21
IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a…
- CVE-2021-29943CRITICALCVSS 9.1EG 9.12021-04-13
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorre…
- CVE-2021-29959MEDIUMCVSS 4.3EG 4.32021-06-24
When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording …
- CVE-2021-29961MEDIUMCVSS 4.3EG 4.32021-06-24
When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.
- CVE-2021-3006HIGHCVSS 7.5EG 7.52021-01-03
The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021.
- CVE-2021-30120CRITICALCVSS 9.9EG 9.92021-07-09
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed desc…
- CVE-2021-30127HIGHCVSS 7.3EG 7.32021-04-03
TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: man…
- CVE-2021-30144MEDIUMCVSS 4.3EG 4.32021-04-06
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboa…
- CVE-2021-30192CRITICALCVSS 9.8EG 9.82021-05-25
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
- CVE-2021-30205MEDIUMCVSS 5.3EG 5.32023-06-27
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.
- CVE-2021-30344HIGHCVSS 7.5EG 7.52022-06-14
Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdrag…
- CVE-2021-3044CRITICALCVSS 9.8EG 9.82021-06-22
An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: C…
- CVE-2021-3049MEDIUMCVSS 2.6EG 4.32021-09-08
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are awar…
- CVE-2021-30503CRITICALCVSS 9.8EG 9.82021-04-13
The unofficial GLSL Linting extension before 1.4.0 for Visual Studio Code allows remote code execution via a crafted glslangValidatorPath in the workspace configuration.
- CVE-2021-30531MEDIUMCVSS 6.5EG 6.52021-06-07
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2021-30532MEDIUMCVSS 4.3EG 4.32021-06-07
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2021-30533CRITICALCVSS 6.5EG 9.0⚠ KEV2021-06-07
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
- CVE-2021-30534MEDIUMCVSS 6.5EG 6.52021-06-07
Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2021-30537MEDIUMCVSS 4.3EG 4.32021-06-07
Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.
- CVE-2021-30538MEDIUMCVSS 4.3EG 4.32021-06-07
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2021-30539MEDIUMCVSS 5.4EG 5.42021-06-07
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2021-30571CRITICALCVSS 9.6EG 9.62021-08-03
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2021-30577HIGHCVSS 7.8EG 7.82021-08-03
Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
- CVE-2021-30580MEDIUMCVSS 6.5EG 6.52021-08-03
Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.
- CVE-2021-30583MEDIUMCVSS 6.5EG 6.52021-08-03
Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-3062HIGHCVSS 8.1EG 8.82021-11-10
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. …
- CVE-2021-30638HIGHCVSS 7.5EG 7.52021-04-27
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue a…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →