CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,110 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 25 of 83
- CVE-2021-38608HIGHCVSS 7.8EG 7.82021-08-16
Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent.
- CVE-2021-38615HIGHCVSS 6.3EG 8.12021-09-07
In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-in user (guest, standard, or admin) to view and modify information.
- CVE-2021-38616HIGHCVSS 7.6EG 8.82021-09-07
In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could mod…
- CVE-2021-38617HIGHCVSS 8.8EG 8.82021-09-07
In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to create a super user account with a defined password. This directly leads to privilege escalation.
- CVE-2021-38789HIGHCVSS 7.5EG 7.52022-01-19
Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which a third-party app could change system settings.
- CVE-2021-38900MEDIUMCVSS 6.5EG 6.52021-12-21
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.
- CVE-2021-38971MEDIUMCVSS 4.9EG 4.92022-03-14
IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620.
- CVE-2021-38977MEDIUMCVSS 4.3EG 4.32021-11-15
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this …
- CVE-2021-39052CRITICALCVSS 9.8EG 9.82021-12-13
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.
- CVE-2021-39070CRITICALCVSS 9.8EG 9.82022-02-02
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.
- CVE-2021-39119MEDIUMCVSS 5.3EG 5.32021-09-01
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue no…
- CVE-2021-39138MEDIUMCVSS 4.8EG 4.82021-08-19
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup users and also allow users to login anonymously. Prior to version 4.5.1, when an anonymous us…
- CVE-2021-39155HIGHCVSS 8.3EG 8.32021-08-24
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html…
- CVE-2021-39156HIGHCVSS 8.1EG 8.12021-08-24
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a…
- CVE-2021-39163LOWCVSS 3.1EG 3.12021-08-31
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulner…
- CVE-2021-39164LOWCVSS 3.1EG 3.12021-08-31
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room…
- CVE-2021-39206HIGHCVSS 8.6EG 8.62021-09-09
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or authorization policy dec…
- CVE-2021-39234MEDIUMCVSS 6.8EG 6.82021-11-19
In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.
- CVE-2021-39291HIGHCVSS 8.8EG 8.82021-08-23
Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, N…
- CVE-2021-39321HIGHCVSS 8.8EG 8.82021-10-21
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function…
- CVE-2021-39341HIGHCVSS 8.2EG 8.22021-11-01
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file tha…
- CVE-2021-3956MEDIUMCVSS 4.3EG 5.32022-05-18
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that sup…
- CVE-2021-39630HIGHCVSS 7.8EG 7.82022-01-14
In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges ne…
- CVE-2021-39742MEDIUMCVSS 5.5EG 5.52022-03-30
In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for expl…
- CVE-2021-39743HIGHCVSS 7.8EG 7.82022-03-30
In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
- CVE-2021-39749HIGHCVSS 7.8EG 7.82022-03-30
In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…
- CVE-2021-39750HIGHCVSS 7.8EG 7.82022-03-30
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2021-39751MEDIUMCVSS 5.5EG 5.52022-03-30
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interact…
- CVE-2021-39753MEDIUMCVSS 5.5EG 5.52022-03-30
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User int…
- CVE-2021-39789HIGHCVSS 7.8EG 7.82022-03-30
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro…
- CVE-2021-39790HIGHCVSS 7.8EG 7.82022-03-30
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for e…
- CVE-2021-39799HIGHCVSS 7.8EG 7.82022-04-12
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…
- CVE-2021-39802HIGHCVSS 7.8EG 7.82022-04-12
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…
- CVE-2021-39876MEDIUMCVSS 4.3EG 4.32022-03-28
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.
- CVE-2021-39883MEDIUMCVSS 4.3EG 4.32021-10-04
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all pa…
- CVE-2021-39891MEDIUMCVSS 5.9EG 5.92021-10-05
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
- CVE-2021-39902MEDIUMCVSS 4.3EG 4.32021-11-04
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.
- CVE-2021-39903MEDIUMCVSS 6.5EG 6.52021-11-04
In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as…
- CVE-2021-39904MEDIUMCVSS 4.3EG 4.32021-11-05
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge R…
- CVE-2021-39911MEDIUMCVSS 4.3EG 4.32021-11-05
An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and M…
- CVE-2021-39918LOWCVSS 3.1EG 3.12021-12-13
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability wh…
- CVE-2021-39930MEDIUMCVSS 4.3EG 4.32021-12-13
Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates
- CVE-2021-39934MEDIUMCVSS 4.3EG 4.32021-12-13
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.…
- CVE-2021-39936LOWCVSS 3.5EG 3.52021-12-13
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy tok…
- CVE-2021-39943MEDIUMCVSS 4.3EG 4.32022-02-09
An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a use…
- CVE-2021-39945LOWCVSS 2.7EG 2.72021-12-13
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to ap…
- CVE-2021-39986MEDIUMCVSS 5.5EG 5.52022-02-09
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-39991MEDIUMCVSS 5.5EG 5.52022-02-09
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-39994CRITICALCVSS 9.8EG 9.82022-02-09
There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2021-40016MEDIUMCVSS 6.5EG 6.52022-07-12
Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →