CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 6 of 83
- CVE-2019-11684CRITICALCVSS 9.9EG 9.92021-02-26
Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. T…
- CVE-2019-11724MEDIUMCVSS 6.1EG 6.12019-07-23
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for mali…
- CVE-2019-11862HIGHCVSS 8.1EG 8.12020-08-21
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
- CVE-2019-1192MEDIUMCVSS 4.3EG 4.32019-08-14
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that…
- CVE-2019-12419CRITICALCVSS 9.8EG 9.82019-11-06
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated p…
- CVE-2019-12492MEDIUMCVSS 6.5EG 6.52019-06-06
Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services.
- CVE-2019-12648HIGHCVSS 8.8EG 8.82019-09-25
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability i…
- CVE-2019-12671HIGHCVSS 7.8EG 7.82019-09-25
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insuffici…
- CVE-2019-12837MEDIUMCVSS 4.3EG 4.32019-12-31
The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.
- CVE-2019-1289MEDIUMCVSS 5.5EG 5.52019-09-11
An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.
- CVE-2019-13001MEDIUMCVSS 4.3EG 4.32020-03-10
An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthorized users to add comments to a private snippet. It allows aut…
- CVE-2019-13337HIGHCVSS 7.5EG 7.52019-07-09
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The websi…
- CVE-2019-13386HIGHCVSS 8.8EG 8.82019-07-26
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.
- CVE-2019-13417MEDIUMCVSS 5.3EG 5.32019-08-12
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
- CVE-2019-13716MEDIUMCVSS 4.3EG 4.32019-11-25
Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2019-14236CRITICALCVSS 9.8EG 9.82019-09-12
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instru…
- CVE-2019-14237CRITICALCVSS 9.8EG 9.82019-09-12
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.
- CVE-2019-14711HIGHCVSS 7.0EG 7.02020-10-23
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.
- CVE-2019-14811HIGHCVSS 7.8EG 7.82019-09-03
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file c…
- CVE-2019-14813CRITICALCVSS 9.8EG 9.82019-09-06
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could…
- CVE-2019-14817HIGHCVSS 7.8EG 7.82019-09-03
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript fil…
- CVE-2019-14832HIGHCVSS 7.5EG 7.52019-10-15
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized inf…
- CVE-2019-14843HIGHCVSS 8.8EG 8.82020-01-07
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly cond…
- CVE-2019-14924HIGHCVSS 7.5EG 7.52019-08-10
An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerability, an adversary can make an inaccessi…
- CVE-2019-14995MEDIUMCVSS 5.3EG 5.32019-09-11
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
- CVE-2019-15059HIGHCVSS 7.5EG 7.52021-04-12
In Liberty lisPBX 2.0-4, configuration backup files can be retrieved remotely from /backup/lispbx-CONF-YYYY-MM-DD.tar or /backup/lispbx-CDR-YYYY-MM-DD.tar without authentication or authorization. These configuration files have all PBX info…
- CVE-2019-15729HIGHCVSS 7.5EG 7.52019-09-17
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.
- CVE-2019-15900CRITICALCVSS 9.8EG 9.82019-10-18
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in …
- CVE-2019-15941CRITICALCVSS 9.8EG 9.82019-09-25
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDA…
- CVE-2019-1603HIGHCVSS 7.8EG 7.82019-03-08
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level. The vulnerability is due to insufficient authorization enforcement. An attacker …
- CVE-2019-1604HIGHCVSS 7.8EG 7.82019-03-08
A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to an incorrect authorization check o…
- CVE-2019-16114CRITICALCVSS 9.8EG 9.82019-09-09
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads f…
- CVE-2019-16244CRITICALCVSS 9.8EG 9.82020-07-22
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
- CVE-2019-1626HIGHCVSS 8.8EG 8.82019-06-20
A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly au…
- CVE-2019-16538HIGHCVSS 8.8EG 8.82019-11-21
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.
- CVE-2019-16651MEDIUMCVSS 5.3EG 5.32021-09-20
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a us…
- CVE-2019-1667LOWCVSS 3.3EG 3.32019-02-21
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient authorization controls. An attac…
- CVE-2019-16884HIGHCVSS 7.5EG 7.52019-09-25
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /…
- CVE-2019-17014HIGHCVSS 7.4EG 7.42020-01-08
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
- CVE-2019-17190HIGHCVSS 7.8EG 7.82020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe ch…
- CVE-2019-17191HIGHCVSS 7.5EG 7.52019-10-05
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the …
- CVE-2019-18949HIGHCVSS 7.5EG 7.52019-11-14
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
- CVE-2019-1912CRITICALCVSS 9.1EG 9.12019-08-07
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the…
- CVE-2019-19200HIGHCVSS 8.8EG 8.82020-10-06
REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.
- CVE-2019-19520HIGHCVSS 7.8EG 7.82019-12-05
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.
- CVE-2019-19597HIGHCVSS 8.8EG 8.82019-12-05
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.
- CVE-2019-19681HIGHCVSS 8.8EG 8.82019-12-26
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vul…
- CVE-2019-19984MEDIUMCVSS 6.3EG 6.32019-12-26
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
- CVE-2019-20213HIGHCVSS 7.5EG 7.52020-01-02
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
- CVE-2019-20484HIGHCVSS 8.1EG 8.12021-01-05
An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →