CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,429 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 2 of 89
- CVE-2016-20005CRITICALCVSS 9.8EG 9.82021-01-01
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
- CVE-2016-20075HIGHCVSS 8.8EG 8.82026-06-15
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields fun…
- CVE-2016-3131MEDIUMCVSS 6.5EG 6.52019-11-26
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
- CVE-2016-4178MEDIUMCVSS 4.3EG 5.32016-07-13
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vect…
- CVE-2016-4514HIGHCVSS 7.7EG 7.72016-06-19
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy.
- CVE-2016-4572HIGHCVSS 8.8EG 8.82019-11-26
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
- CVE-2016-6353MEDIUMCVSS 6.5EG 6.52019-11-26
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
- CVE-2016-6591HIGHCVSS 7.1EG 7.12020-01-08
A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.
- CVE-2016-6797HIGHCVSS 7.5EG 7.52017-08-10
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explici…
- CVE-2016-9575MEDIUMCVSS 6.3EG 6.32018-03-13
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw …
- CVE-2017-0881MEDIUMCVSS 4.3EG 4.32017-03-28
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an…
- CVE-2017-0894MEDIUMCVSS 4.3EG 4.32017-05-08
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
- CVE-2017-0910HIGHCVSS 8.8EG 8.82017-11-27
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
- CVE-2017-0920MEDIUMCVSS 4.3EG 4.32018-03-22
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and…
- CVE-2017-0922HIGHCVSS 7.5EG 7.52018-03-21
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
- CVE-2017-0926HIGHCVSS 8.8EG 8.82018-03-21
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.
- CVE-2017-0927MEDIUMCVSS 6.5EG 6.52018-03-21
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
- CVE-2017-10379MEDIUMCVSS 6.5EG 6.52017-10-19
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows lo…
- CVE-2017-10805HIGHCVSS 8.8EG 8.82017-07-04
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.
- CVE-2017-12112HIGHCVSS 8.1EG 8.12018-01-19
An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in a…
- CVE-2017-12113HIGHCVSS 8.1EG 8.12018-01-19
An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in …
- CVE-2017-12114MEDIUMCVSS 6.8EG 6.82018-01-19
An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in aut…
- CVE-2017-12115HIGHCVSS 8.1EG 8.12018-01-19
An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting…
- CVE-2017-12116HIGHCVSS 8.1EG 8.12018-01-19
An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting …
- CVE-2017-12117HIGHCVSS 8.1EG 8.12018-01-19
An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in aut…
- CVE-2017-12118HIGHCVSS 8.1EG 8.12018-01-19
An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). An attacker can send JSON to trigger this vulnerability.
- CVE-2017-12196MEDIUMCVSS 4.8EG 4.82018-04-18
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This a…
- CVE-2017-12197MEDIUMCVSS 6.5EG 6.52018-01-18
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive…
- CVE-2017-12261HIGHCVSS 7.8EG 7.82017-11-02
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to…
- CVE-2017-1233MEDIUMCVSS 6.7EG 6.72018-01-31
IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912.
- CVE-2017-15091HIGHCVSS 7.1EG 7.12018-01-23
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the…
- CVE-2017-15695HIGHCVSS 8.8EG 8.82018-06-13
When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployme…
- CVE-2017-1628MEDIUMCVSS 6.5EG 6.52017-11-27
IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.
- CVE-2017-16743CRITICALCVSS 9.8EG 9.82018-01-12
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing a…
- CVE-2017-16773HIGHCVSS 6.5EG 8.82018-07-05
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode.
- CVE-2017-16778MEDIUMCVSS 4.6EG 4.62019-12-24
An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level…
- CVE-2017-16858MEDIUMCVSS 6.8EG 6.82018-01-31
The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a d…
- CVE-2017-1700MEDIUMCVSS 6.5EG 6.52018-04-24
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quali…
- CVE-2017-17067CRITICALCVSS 9.8EG 9.82017-11-30
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intend…
- CVE-2017-17323MEDIUMCVSS 4.3EG 4.32018-03-09
Huawei iBMC V200R002C10; V200R002C20; V200R002C30 have an improper authorization vulnerability. The software incorrectly performs an authorization check when a normal user attempts to access certain information which is supposed to be acce…
- CVE-2017-1766MEDIUMCVSS 4.3EG 4.32018-03-30
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
- CVE-2017-17668HIGHCVSS 7.5EG 7.52018-03-20
Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.
- CVE-2017-17708MEDIUMCVSS 4.3EG 4.32018-07-31
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.
- CVE-2017-18095MEDIUMCVSS 5.3EG 5.32018-02-19
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vul…
- CVE-2017-20066HIGHCVSS 5.3EG 7.82022-06-20
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The ex…
- CVE-2017-2305HIGHCVSS 8.8EG 8.82017-05-30
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
- CVE-2017-2306HIGHCVSS 8.8EG 8.82017-05-30
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
- CVE-2017-2599MEDIUMCVSS 5.4EG 5.42018-04-11
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
- CVE-2017-2611MEDIUMCVSS 4.3EG 4.32018-05-08
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read ac…
- CVE-2017-2632MEDIUMCVSS 4.9EG 4.92018-07-27
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenan…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →