CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 37 of 83
- CVE-2022-40773HIGHCVSS 8.8EG 8.82022-11-12
Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.
- CVE-2022-40816MEDIUMCVSS 6.5EG 6.52022-09-27
Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web…
- CVE-2022-40843MEDIUMCVSS 4.9EG 4.92022-11-15
The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the…
- CVE-2022-4090HIGHCVSS 4.3EG 8.82022-11-24
A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request forgery. The attack m…
- CVE-2022-41091CRITICALCVSS 5.4EG 9.0⚠ KEV2022-11-09
Windows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2022-41155CRITICALCVSS 5.3EG 9.82022-11-19
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
- CVE-2022-41230MEDIUMCVSS 4.3EG 4.32022-09-21
Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish b…
- CVE-2022-41274MEDIUMCVSS 6.5EG 6.52022-12-13
SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can…
- CVE-2022-41326CRITICALCVSS 9.8EG 9.82022-11-22
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the…
- CVE-2022-41574HIGHCVSS 7.5EG 7.52022-10-07
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact addres…
- CVE-2022-41610MEDIUMCVSS 5.0EG 5.02023-05-10
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-4167HIGHCVSS 5.3EG 7.52023-01-12
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to rev…
- CVE-2022-41797MEDIUMCVSS 6.5EG 6.52022-10-24
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website v…
- CVE-2022-41918MEDIUMCVSS 6.3EG 6.32022-11-15
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are…
- CVE-2022-41923CRITICALCVSS 9.1EG 9.12022-11-23
Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor…
- CVE-2022-41944LOWCVSS 3.5EG 3.52022-11-28
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. …
- CVE-2022-41962LOWCVSS 2.7EG 2.72022-12-16
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status feature to set any emoji s…
- CVE-2022-41970LOWCVSS 2.6EG 2.62022-12-01
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be d…
- CVE-2022-42344HIGHCVSS 8.8EG 8.82022-10-20
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposu…
- CVE-2022-42351MEDIUMCVSS 4.3EG 4.32022-12-16
Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to disclose low level…
- CVE-2022-42724MEDIUMCVSS 4.3EG 4.32022-10-10
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
- CVE-2022-42788MEDIUMCVSS 5.5EG 5.52022-11-01
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious application may be able to read sensitive location information.
- CVE-2022-42849HIGHCVSS 7.8EG 7.82022-12-15
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
- CVE-2022-42903LOWCVSS 3.3EG 3.32022-11-17
Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
- CVE-2022-42975HIGHCVSS 7.5EG 7.52022-10-17
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
- CVE-2022-42978HIGHCVSS 7.5EG 7.52022-11-15
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.
- CVE-2022-4315MEDIUMCVSS 5.0EG 6.52023-03-08
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
- CVE-2022-43400CRITICALCVSS 9.8EG 9.82022-10-21
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of…
- CVE-2022-43438HIGHCVSS 8.8EG 8.82023-01-03
The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access restrictions, to make API functions calls, …
- CVE-2022-43465MEDIUMCVSS 5.0EG 5.02023-05-10
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-4349MEDIUMCVSS 4.3EG 6.82022-12-08
A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exp…
- CVE-2022-43515CRITICALCVSS 5.3EG 9.82022-12-05
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained a…
- CVE-2022-43770HIGHCVSS 5.4EG 8.12023-04-11
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.
- CVE-2022-43872MEDIUMCVSS 5.3EG 5.32022-12-20
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.
- CVE-2022-43940HIGHCVSS 8.8EG 8.82023-04-03
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service.
- CVE-2022-4397MEDIUMCVSS 4.3EG 6.52022-12-10
A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-sit…
- CVE-2022-44039CRITICALCVSS 9.8EG 9.82022-12-05
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecu…
- CVE-2022-44565MEDIUMCVSS 5.3EG 5.32022-12-23
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
- CVE-2022-44698CRITICALCVSS 5.4EG 9.0⚠ KEV2022-12-13
Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2022-44699MEDIUMCVSS 5.5EG 5.52022-12-13
Azure Network Watcher Agent Security Feature Bypass Vulnerability
- CVE-2022-45128MEDIUMCVSS 5.0EG 5.02023-05-10
Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-45168MEDIUMCVSS 6.5EG 6.52024-06-10
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application…
- CVE-2022-45172CRITICALCVSS 9.8EG 9.82023-01-31
An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/cha…
- CVE-2022-45190MEDIUMCVSS 5.3EG 5.32023-02-08
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.
- CVE-2022-45353HIGHCVSS 4.3EG 8.12023-01-14
Broken Access Control in Betheme theme <= 26.6.1 on WordPress.
- CVE-2022-45383MEDIUMCVSS 6.5EG 6.52022-11-15
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users w…
- CVE-2022-45435MEDIUMCVSS 6.8EG 6.82023-01-31
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6, and all prior v…
- CVE-2022-45544HIGHCVSS 8.8EG 8.82023-02-07
Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally a…
- CVE-2022-45636HIGHCVSS 8.1EG 8.12023-03-21
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.
- CVE-2022-45760HIGHCVSS 8.8EG 8.82022-12-12
SENS v1.0 is vulnerable to Incorrect Access Control vulnerability.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →