CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 9 of 83
- CVE-2020-12500CRITICALCVSS 9.8EG 9.82020-10-15
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated …
- CVE-2020-12503HIGHCVSS 7.2EG 7.22020-10-15
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G…
- CVE-2020-12504CRITICALCVSS 9.8EG 9.82020-10-15
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G…
- CVE-2020-12621MEDIUMCVSS 6.1EG 6.12020-09-02
The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component.
- CVE-2020-12643MEDIUMCVSS 4.3EG 4.32020-08-31
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
- CVE-2020-12668MEDIUMCVSS 6.5EG 6.52021-02-19
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
- CVE-2020-12691HIGHCVSS 8.8EG 8.82020-05-07
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then perform an update to the credential user…
- CVE-2020-12720CRITICALCVSS 9.8EG 9.82020-05-08
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
- CVE-2020-12733HIGHCVSS 7.5EG 7.52021-07-15
Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account.
- CVE-2020-12745HIGHCVSS 7.5EG 7.52020-05-11
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipboard content via USSD. The Samsung ID is SVE-2019-16556 (May 2020).
- CVE-2020-12776MEDIUMCVSS 6.6EG 6.62020-09-01
Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie.
- CVE-2020-12780HIGHCVSS 7.5EG 7.52020-08-10
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
- CVE-2020-12874CRITICALCVSS 9.8EG 9.82020-05-14
Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.
- CVE-2020-12875MEDIUMCVSS 6.3EG 6.32020-05-14
Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality by manipulating specific parameters within the application.
- CVE-2020-12876HIGHCVSS 7.5EG 7.52020-05-14
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.
- CVE-2020-12954MEDIUMCVSS 5.5EG 5.52021-11-16
A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.
- CVE-2020-13263HIGHCVSS 7.5EG 7.52020-06-19
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
- CVE-2020-13272HIGHCVSS 7.5EG 7.52020-06-19
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
- CVE-2020-13275HIGHCVSS 8.0EG 8.02020-06-19
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
- CVE-2020-13276HIGHCVSS 7.4EG 7.42020-06-19
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
- CVE-2020-13277MEDIUMCVSS 6.3EG 6.32020-06-19
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
- CVE-2020-13284MEDIUMCVSS 6.5EG 6.52020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token
- CVE-2020-13300CRITICALCVSS 8.0EG 10.02020-09-14
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.
- CVE-2020-13303HIGHCVSS 7.1EG 7.12020-09-15
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.
- CVE-2020-13313MEDIUMCVSS 4.3EG 4.32020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.
- CVE-2020-13318MEDIUMCVSS 6.4EG 6.42020-09-14
A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.
- CVE-2020-13320MEDIUMCVSS 6.5EG 6.52020-09-30
An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.
- CVE-2020-13322HIGHCVSS 7.2EG 7.22020-09-30
A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.
- CVE-2020-13323HIGHCVSS 7.7EG 7.72020-09-30
A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos
- CVE-2020-13334MEDIUMCVSS 5.9EG 5.92020-10-07
In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentiality attribute of issue via mutation GraphQL query
- CVE-2020-13335MEDIUMCVSS 4.3EG 4.32020-10-07
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.
- CVE-2020-13358MEDIUMCVSS 4.7EG 4.72020-11-17
A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.
- CVE-2020-13593HIGHCVSS 8.8EG 8.82020-08-31
The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipped if the Link Laye…
- CVE-2020-13676MEDIUMCVSS 6.5EG 6.52022-02-11
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installe…
- CVE-2020-13696MEDIUMCVSS 4.4EG 4.42020-06-08
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local …
- CVE-2020-13834HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict use of Android Debug Bridge (adb) for arbitrary installations. The Samsung ID is SVE-2020-…
- CVE-2020-13957CRITICALCVSS 9.8EG 9.82020-10-13
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authenticati…
- CVE-2020-14011CRITICALCVSS 9.8EG 9.82020-06-15
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled D…
- CVE-2020-14106MEDIUMCVSS 5.5EG 5.52021-04-08
The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.
- CVE-2020-14110HIGHCVSS 7.8EG 7.82022-01-18
AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.
- CVE-2020-14121MEDIUMCVSS 5.5EG 5.52022-04-21
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.
- CVE-2020-14165MEDIUMCVSS 5.3EG 5.32020-07-01
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
- CVE-2020-14196MEDIUMCVSS 5.3EG 5.32020-07-01
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.
- CVE-2020-14214MEDIUMCVSS 6.5EG 6.52020-06-16
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can register a new account that will have access to all tickets of an arbitrary Organization.
- CVE-2020-14215HIGHCVSS 7.5EG 7.52020-08-21
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
- CVE-2020-14292MEDIUMCVSS 5.7EG 5.72020-09-09
In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which re…
- CVE-2020-14321HIGHCVSS 8.8EG 8.82022-08-16
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
- CVE-2020-14486MEDIUMCVSS 6.3EG 6.32020-07-29
An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.
- CVE-2020-14944CRITICALCVSS 9.8EG 9.82020-06-22
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exp…
- CVE-2020-15084HIGHCVSS 7.7EG 7.72020-06-30
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may l…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →