CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 30 of 83
- CVE-2022-21707MEDIUMCVSS 6.3EG 6.32022-01-21
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally requi…
- CVE-2022-21713MEDIUMCVSS 4.3EG 4.32022-02-08
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view …
- CVE-2022-21812HIGHCVSS 7.8EG 7.82022-08-18
Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-21825HIGHCVSS 7.8EG 7.82022-02-09
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
- CVE-2022-2188MEDIUMCVSS 6.5EG 6.52022-11-07
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the …
- CVE-2022-21894MEDIUMCVSS 4.4EG 4.42022-01-11
Secure Boot Security Feature Bypass Vulnerability
- CVE-2022-21899MEDIUMCVSS 5.5EG 5.52022-01-11
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
- CVE-2022-21913HIGHCVSS 5.3EG 7.52022-01-11
Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
- CVE-2022-22048MEDIUMCVSS 6.1EG 6.12022-07-12
BitLocker Security Feature Bypass Vulnerability
- CVE-2022-22091HIGHCVSS 7.5EG 7.52022-09-16
Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdrag…
- CVE-2022-22157HIGHCVSS 7.2EG 7.22022-01-19
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn…
- CVE-2022-22167HIGHCVSS 7.2EG 7.22022-01-19
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn…
- CVE-2022-22190HIGHCVSS 7.4EG 7.52022-04-14
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration i…
- CVE-2022-22254HIGHCVSS 7.5EG 7.52022-04-11
A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-22272MEDIUMCVSS 4.0EG 4.02022-01-10
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission
- CVE-2022-22288HIGHCVSS 7.5EG 7.52022-01-10
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
- CVE-2022-2229HIGHCVSS 7.5EG 7.52022-07-01
An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in p…
- CVE-2022-22300HIGHCVSS 4.3EG 8.82022-03-01
A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 throug…
- CVE-2022-22307MEDIUMCVSS 4.4EG 4.42023-06-15
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753.
- CVE-2022-22326LOWCVSS 3.3EG 3.32022-08-01
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
- CVE-2022-2243MEDIUMCVSS 5.0EG 5.02022-07-01
An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows authenticated users to enumerate issues in non-linked sentry projects.
- CVE-2022-2244MEDIUMCVSS 4.3EG 4.32022-07-01
An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error track…
- CVE-2022-22616MEDIUMCVSS 5.5EG 5.52022-05-26
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
- CVE-2022-22618HIGHCVSS 7.8EG 7.82022-03-18
This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. A user may be able to bypass the Emergency SOS passcode prompt.
- CVE-2022-22663MEDIUMCVSS 5.5EG 5.52022-05-26
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 15.4 and iPadOS 15.4, Security Update 2022-004 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.6. A malicious application may bypas…
- CVE-2022-22754MEDIUMCVSS 6.5EG 6.52022-12-22
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, …
- CVE-2022-22798HIGHCVSS 6.8EG 8.82022-05-12
Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP, then he n…
- CVE-2022-22967HIGHCVSS 8.8EG 8.82022-06-23
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is …
- CVE-2022-22978CRITICALCVSS 9.8EG 9.82022-05-19
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the…
- CVE-2022-23009HIGHCVSS 7.2EG 7.22022-01-25
On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions which have reached En…
- CVE-2022-2303MEDIUMCVSS 4.3EG 4.32022-08-05
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement…
- CVE-2022-23033HIGHCVSS 7.8EG 7.82022-01-25
arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do no…
- CVE-2022-23134CRITICALCVSS 3.7EG 9.0⚠ KEV2022-01-13
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Fro…
- CVE-2022-23139HIGHCVSS 8.8EG 8.82022-05-12
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file pe…
- CVE-2022-23182HIGHCVSS 8.8EG 8.82022-08-18
Improper access control in the Intel(R) Data Center Manager software before version 4.1 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
- CVE-2022-23255MEDIUMCVSS 5.9EG 5.92022-02-09
Microsoft OneDrive for Android Security Feature Bypass Vulnerability
- CVE-2022-2326HIGHCVSS 6.4EG 8.12022-08-05
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through…
- CVE-2022-23433MEDIUMCVSS 4.3EG 5.32022-02-11
Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remote…
- CVE-2022-23442MEDIUMCVSS 4.3EG 4.32022-08-03
An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information …
- CVE-2022-23443HIGHCVSS 7.5EG 7.52022-05-04
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
- CVE-2022-23451HIGHCVSS 8.1EG 8.12022-09-06
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an atta…
- CVE-2022-23452MEDIUMCVSS 4.9EG 4.92022-09-01
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of ser…
- CVE-2022-23473MEDIUMCVSS 4.3EG 4.32022-12-13
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.148, Authorizations are not properly verified when accessing MediaWiki standalone resources. Users with read only…
- CVE-2022-23488MEDIUMCVSS 6.5EG 6.52022-12-17
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the backend, which allows …
- CVE-2022-23490MEDIUMCVSS 4.3EG 4.32022-12-16
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the c…
- CVE-2022-2354HIGHCVSS 7.2EG 7.22022-08-15
The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.
- CVE-2022-23551MEDIUMCVSS 5.3EG 5.32022-12-21
aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this …
- CVE-2022-23553HIGHCVSS 7.5EG 7.52022-12-28
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds.
- CVE-2022-23615MEDIUMCVSS 5.4EG 5.42022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can save a document with the right of the current user which allow accessing API requi…
- CVE-2022-23627MEDIUMCVSS 5.0EG 5.02022-02-08
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of t…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →