CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 23 of 83
- CVE-2021-33663MEDIUMCVSS 5.3EG 5.32021-06-09
SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthor…
- CVE-2021-33686MEDIUMCVSS 5.3EG 5.32021-09-14
Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but does not have control over kind or degree.
- CVE-2021-33718MEDIUMCVSS 5.3EG 5.32021-07-13
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions < V8.18.7), Mendix Applications using Mendix 9 (All versions < V9.3.0). Write access chec…
- CVE-2021-33786HIGHCVSS 8.1EG 8.82021-07-14
Windows LSA Security Feature Bypass Vulnerability
- CVE-2021-33881MEDIUMCVSS 4.2EG 4.22021-06-06
On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is use…
- CVE-2021-33895HIGHCVSS 8.1EG 8.12021-06-25
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password r…
- CVE-2021-33981MEDIUMCVSS 4.3EG 4.32021-09-08
An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and im…
- CVE-2021-34110HIGHCVSS 7.8EG 7.82021-07-08
WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.
- CVE-2021-34203HIGHCVSS 8.1EG 8.12021-06-16
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password a…
- CVE-2021-34272HIGHCVSS 7.5EG 7.52021-08-03
A security flaw in the 'owned' function of a smart contract implementation for RobotCoin (RBTC), a tradeable Ethereum ERC20 token, allows attackers to hijack victim accounts and arbitrarily increase the digital supply of assets.
- CVE-2021-34273HIGHCVSS 7.5EG 7.52021-08-03
A security flaw in the 'owned' function of a smart contract implementation for BTC2X (B2X), a tradeable Ethereum ERC20 token, allows attackers to hijack victim accounts and arbitrarily increase the digital supply of assets.
- CVE-2021-34396LOWCVSS 3.0EG 3.02021-06-22
Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, which would result in limited denial of service.
- CVE-2021-34434MEDIUMCVSS 5.3EG 5.32021-08-30
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are …
- CVE-2021-34466MEDIUMCVSS 5.7EG 6.12021-07-16
Windows Hello Security Feature Bypass Vulnerability
- CVE-2021-34469HIGHCVSS 8.2EG 8.22021-07-14
Microsoft Office Security Feature Bypass Vulnerability
- CVE-2021-34548HIGHCVSS 7.5EG 7.52021-06-29
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.
- CVE-2021-3456HIGHCVSS 7.1EG 7.12022-03-30
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to a…
- CVE-2021-3457MEDIUMCVSS 6.1EG 6.12021-05-12
An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacke…
- CVE-2021-34626MEDIUMCVSS 4.3EG 4.32021-07-07
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
- CVE-2021-34627MEDIUMCVSS 4.3EG 4.32021-07-07
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
- CVE-2021-34647MEDIUMCVSS 6.5EG 6.52021-09-22
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticat…
- CVE-2021-34648MEDIUMCVSS 6.4EG 6.42021-09-22
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers…
- CVE-2021-3469MEDIUMCVSS 5.4EG 5.42021-06-03
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate …
- CVE-2021-3493CRITICALCVSS 8.8EG 9.0⚠ KEV2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along…
- CVE-2021-3499MEDIUMCVSS 5.6EG 5.62021-06-02
A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, inte…
- CVE-2021-3511MEDIUMCVSS 4.3EG 4.32021-04-28
Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP fi…
- CVE-2021-35112HIGHCVSS 8.4EG 8.42022-06-14
A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
- CVE-2021-3512HIGHCVSS 8.8EG 8.82021-04-28
Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 f…
- CVE-2021-35197HIGHCVSS 7.5EG 7.52021-07-02
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki…
- CVE-2021-35202MEDIUMCVSS 4.3EG 4.32021-09-30
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.
- CVE-2021-35248MEDIUMCVSS 6.8EG 6.82021-12-20
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
- CVE-2021-35249MEDIUMCVSS 4.3EG 4.32022-05-17
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only …
- CVE-2021-35336CRITICALCVSS 9.8EG 9.82021-07-01
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privil…
- CVE-2021-35368CRITICALCVSS 9.8EG 9.82021-11-05
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
- CVE-2021-35465LOWCVSS 3.4EG 3.42021-08-23
Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-secure handler may have read or write access to part of a Secure context. This affects Arm Cortex-M33 r0p0 through r1p0,…
- CVE-2021-35526HIGHCVSS 6.3EG 7.82021-09-08
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SD…
- CVE-2021-35534HIGHCVSS 7.2EG 7.22021-11-18
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product do…
- CVE-2021-35550MEDIUMCVSS 5.9EG 5.92021-10-20
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Dif…
- CVE-2021-35551MEDIUMCVSS 5.5EG 5.52021-10-20
Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network acc…
- CVE-2021-35552MEDIUMCVSS 5.3EG 5.32021-10-20
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Diagnostics). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticat…
- CVE-2021-35553MEDIUMCVSS 5.4EG 6.52021-10-20
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Class Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with netwo…
- CVE-2021-35559MEDIUMCVSS 5.3EG 5.32021-10-20
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0…
- CVE-2021-3560CRITICALCVSS 7.8EG 9.0⚠ KEV2022-02-16
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, creat…
- CVE-2021-3563CRITICALCVSS 7.4EG 9.12022-08-26
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerabili…
- CVE-2021-3577HIGHCVSS 8.8EG 8.92021-11-12
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.
- CVE-2021-35943CRITICALCVSS 9.8EG 9.82021-09-29
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
- CVE-2021-35949MEDIUMCVSS 5.3EG 5.32021-09-07
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
- CVE-2021-36039MEDIUMCVSS 6.5EG 6.52021-09-01
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the `quoteId` parameter. An attacker can abuse this vulnerability to disclose sens…
- CVE-2021-36091MEDIUMCVSS 3.5EG 4.32021-07-26
Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.
- CVE-2021-36132HIGHCVSS 8.8EG 8.82021-07-02
An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with …
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →