CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 34 of 83
- CVE-2022-30717HIGHCVSS 4.0EG 7.52022-06-07
Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.
- CVE-2022-30730MEDIUMCVSS 4.6EG 4.62022-06-07
Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.
- CVE-2022-30745MEDIUMCVSS 4.0EG 5.52022-06-07
Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.
- CVE-2022-30757MEDIUMCVSS 4.0EG 4.02022-07-12
Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.
- CVE-2022-31039MEDIUMCVSS 4.3EG 4.32022-06-27
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to v…
- CVE-2022-31087HIGHCVSS 7.8EG 7.82022-06-27
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (…
- CVE-2022-31107HIGHCVSS 7.1EG 7.12022-07-15
Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth Id…
- CVE-2022-31139MEDIUMCVSS 5.9EG 5.92022-07-11
UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data of UA is protected by JVM and others can only access UA via UA's standard API. The main ap…
- CVE-2022-31153MEDIUMCVSS 6.5EG 6.52022-07-15
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue a…
- CVE-2022-31154MEDIUMCVSS 6.4EG 6.42022-08-01
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the a…
- CVE-2022-31155MEDIUMCVSS 4.3EG 4.32022-08-01
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does n…
- CVE-2022-31168MEDIUMCVSS 5.4EG 5.42022-07-22
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. Th…
- CVE-2022-31178MEDIUMCVSS 4.3EG 4.32022-08-01
eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability has been patched in 4.3.4. Users are ad…
- CVE-2022-31190MEDIUMCVSS 5.3EG 5.32022-08-01
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" ob…
- CVE-2022-31252MEDIUMCVSS 4.4EG 4.42022-10-06
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with acces…
- CVE-2022-31589MEDIUMCVSS 6.5EG 6.52022-06-14
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to…
- CVE-2022-31595HIGHCVSS 8.8EG 8.82022-06-14
SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
- CVE-2022-31609HIGHCVSS 7.8EG 7.82022-08-05
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and con…
- CVE-2022-31644HIGHCVSS 7.8EG 7.82023-06-14
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- CVE-2022-31646HIGHCVSS 7.8EG 7.82023-06-14
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- CVE-2022-31667MEDIUMCVSS 6.4EG 6.42024-11-14
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. By sending a request that attempts to update a robot account, and specifying a …
- CVE-2022-31668HIGHCVSS 7.4EG 7.42024-11-14
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the a…
- CVE-2022-31669MEDIUMCVSS 6.4EG 6.42024-11-14
Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have ac…
- CVE-2022-31670HIGHCVSS 7.7EG 7.72024-11-14
Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access …
- CVE-2022-31671HIGHCVSS 7.4EG 7.42024-11-14
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, m…
- CVE-2022-31675HIGHCVSS 7.5EG 7.52022-08-10
VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.
- CVE-2022-31744MEDIUMCVSS 6.5EG 6.52022-12-22
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird <…
- CVE-2022-31746MEDIUMCVSS 6.5EG 6.52022-12-22
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
- CVE-2022-31876MEDIUMCVSS 5.3EG 5.32022-06-17
netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.
- CVE-2022-3188MEDIUMCVSS 5.3EG 5.32022-12-21
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the late…
- CVE-2022-32255MEDIUMCVSS 5.3EG 5.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized acces…
- CVE-2022-32259MEDIUMCVSS 6.5EG 6.52022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of the affected application contain unit test scripts with sensitive information. An attacker could gai…
- CVE-2022-32290MEDIUMCVSS 4.3EG 4.32022-07-06
The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the devic…
- CVE-2022-32294CRITICALCVSS 9.8EG 9.82022-07-11
Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this c…
- CVE-2022-32295CRITICALCVSS 9.8EG 9.82022-07-01
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.
- CVE-2022-32310CRITICALCVSS 9.8EG 9.82022-07-05
An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.
- CVE-2022-3248MEDIUMCVSS 4.4EG 4.42023-10-05
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
- CVE-2022-32532CRITICALCVSS 9.8EG 9.82022-06-29
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
- CVE-2022-32854MEDIUMCVSS 5.5EG 5.52022-09-20
This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.
- CVE-2022-32945MEDIUMCVSS 4.3EG 4.32022-12-15
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.
- CVE-2022-33174CRITICALCVSS 9.8EG 9.82022-06-13
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interf…
- CVE-2022-33198CRITICALCVSS 9.8EG 9.82022-07-21
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
- CVE-2022-3330MEDIUMCVSS 4.3EG 4.32022-10-17
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
- CVE-2022-33323HIGHCVSS 7.5EG 7.52023-02-02
Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass thr…
- CVE-2022-33632MEDIUMCVSS 4.7EG 4.72022-07-12
Microsoft Office Security Feature Bypass Vulnerability
- CVE-2022-33702MEDIUMCVSS 6.2EG 6.22022-07-12
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
- CVE-2022-33705LOWCVSS 3.3EG 3.32022-07-12
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.
- CVE-2022-33718MEDIUMCVSS 6.2EG 6.22022-08-05
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
- CVE-2022-33913HIGHCVSS 7.5EG 7.52022-06-20
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
- CVE-2022-34046HIGHCVSS 7.5EG 7.52022-07-20
An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →