CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,585 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 1 of 32
- CVE-2013-7245HIGHCVSS 7.5EG 7.52018-04-24
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859.
- CVE-2014-2349MEDIUMCVSS v2 4.6EG 4.62014-05-22
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet pro…
- CVE-2014-6049LOWCVSS 2.7EG 2.72018-08-28
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
- CVE-2014-9945HIGHCVSS 7.8EG 7.82017-06-06
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
- CVE-2014-9950HIGHCVSS 7.8EG 7.82017-06-06
In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
- CVE-2015-1000007HIGHCVSS 7.5EG 7.52016-10-06
Remote file download vulnerability in wptf-image-gallery v1.03
- CVE-2015-10033MEDIUMCVSS 3.5EG 6.52023-01-09
A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. The manipulation leads to improper authorization. The identifier of the patch is 134f5481e…
- CVE-2015-3656HIGHCVSS 7.2EG 7.22017-08-29
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.
- CVE-2015-3954CRITICALCVSS 9.8EG 9.82019-03-25
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unautho…
- CVE-2015-5463CRITICALCVSS 9.8EG 9.82019-04-03
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers to (1) access data of other basic users through arbitrary SQL commands, (2) perform a hor…
- CVE-2015-7463MEDIUMCVSS 4.3EG 4.32018-03-15
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
- CVE-2016-0373MEDIUMCVSS 3.1EG 4.32018-08-30
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.
- CVE-2016-0922CRITICALCVSS 9.8EG 9.82016-09-18
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.
- CVE-2016-1000219HIGHCVSS 7.5EG 7.52017-06-16
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behin…
- CVE-2016-10734CRITICALCVSS 9.8EG 9.82018-10-29
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
- CVE-2016-10848HIGHCVSS 7.2EG 7.22019-08-01
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
- CVE-2016-10859HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
- CVE-2016-1710HIGHCVSS 8.8EG 8.82016-07-23
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attackers to bypass the S…
- CVE-2016-1711HIGHCVSS 8.8EG 8.82016-07-23
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to bypass the Same Orig…
- CVE-2016-3352HIGHCVSS 8.8EG 8.82016-09-14
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attack on NTLM password …
- CVE-2016-4531HIGHCVSS 7.3EG 7.32016-07-28
Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
- CVE-2016-5063MEDIUMCVSS 5.3EG 5.32017-05-02
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.
- CVE-2016-5420HIGHCVSS 7.5EG 7.52016-08-10
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection w…
- CVE-2016-5676HIGHCVSS 7.5EG 8.12016-08-31
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.
- CVE-2016-5788CRITICALCVSS 10.0EG 10.02016-11-25
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier for remote attackers to obtain privileged access via unspecified vectors.
- CVE-2016-5799CRITICALCVSS 9.8EG 9.82016-08-24
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
- CVE-2016-6825CRITICALCVSS 9.8EG 9.82016-09-07
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with softwar…
- CVE-2016-7035HIGHCVSS 8.8EG 8.82018-09-10
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manag…
- CVE-2016-7071HIGHCVSS 8.8EG 8.82018-09-10
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudFo…
- CVE-2016-7077MEDIUMCVSS 4.3EG 4.32018-09-10
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
- CVE-2016-7078MEDIUMCVSS 4.3EG 4.32018-09-10
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an adminis…
- CVE-2016-7097MEDIUMCVSS 4.4EG 4.42016-10-16
The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute…
- CVE-2016-7143HIGHCVSS 8.1EG 8.12016-09-21
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
- CVE-2016-7651MEDIUMCVSS 5.3EG 5.32017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by levera…
- CVE-2016-8443HIGHCVSS 7.8EG 7.82017-01-12
Possible unauthorized memory access in the hypervisor. Incorrect configuration provides access to subsystem page tables. Product: Android. Versions: Kernel 3.18. Android ID: A-32576499. References: QC-CR#964185.
- CVE-2016-8776MEDIUMCVSS 4.6EG 4.62017-04-02
Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass the factory reset protection (FRP) to enter some functional modules without authorization…
- CVE-2016-9217HIGHCVSS 8.8EG 8.82016-12-26
A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used by these products. More Information: CSCus99394. Known Affect…
- CVE-2016-9464MEDIUMCVSS 4.3EG 4.32017-03-28
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group s…
- CVE-2016-9575MEDIUMCVSS 6.3EG 6.32018-03-13
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw …
- CVE-2016-9938MEDIUMCVSS 5.3EG 5.32016-12-12
An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.8-cert4. The chan_sip channel driver has a liberal definitio…
- CVE-2017-0892LOWCVSS 3.5EG 3.52017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.
- CVE-2017-0894MEDIUMCVSS 4.3EG 4.32017-05-08
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
- CVE-2017-0895LOWCVSS 3.5EG 3.52017-05-08
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
- CVE-2017-0896MEDIUMCVSS 6.5EG 6.52017-06-02
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization e…
- CVE-2017-0926HIGHCVSS 8.8EG 8.82018-03-21
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.
- CVE-2017-0927MEDIUMCVSS 6.5EG 6.52018-03-21
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
- CVE-2017-1002151HIGHCVSS 7.5EG 7.52017-09-14
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
- CVE-2017-11398HIGHCVSS 8.8EG 8.82018-01-19
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a v…
- CVE-2017-12160HIGHCVSS 7.2EG 7.22017-10-26
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already comp…
- CVE-2017-16726CRITICALCVSS 9.1EG 9.12018-06-27
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms becaus…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →