CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,430 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 3 of 89
- CVE-2017-2673MEDIUMCVSS 6.8EG 6.82018-07-19
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles i…
- CVE-2017-3183HIGHCVSS 8.8EG 8.82018-07-24
Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full access to privileged database functions. Sage XRT Treasury is a business finance management …
- CVE-2017-3801HIGHCVSS 8.8EG 8.82017-02-15
A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary workflow items with just an end-user profile, a Privilege Escalation Vulnerability. The vulner…
- CVE-2017-3817MEDIUMCVSS 4.3EG 4.32017-04-07
A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More…
- CVE-2017-3891CRITICALCVSS 9.6EG 9.62017-11-14
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to acc…
- CVE-2017-4915HIGHCVSS 7.8EG 7.82017-05-22
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a L…
- CVE-2017-4946HIGHCVSS 7.8EG 7.82018-01-05
The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM.
- CVE-2017-5060MEDIUMCVSS 6.5EG 6.52017-10-27
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
- CVE-2017-5618HIGHCVSS 7.8EG 7.82017-03-20
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
- CVE-2017-6377HIGHCVSS 7.5EG 7.52017-03-16
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
- CVE-2017-6590MEDIUMCVSS 6.3EG 6.32017-03-09
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local files and execute …
- CVE-2017-6672HIGHCVSS 7.5EG 7.52017-07-25
A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x could allow an unauthenticated, remote attacker to bypass ACL rules that have been configure…
- CVE-2017-6816MEDIUMCVSS 4.9EG 4.92017-03-12
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
- CVE-2017-7470CRITICALCVSS 6.5EG 9.82018-07-27
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
- CVE-2017-7505HIGHCVSS 8.8EG 8.82017-05-26
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator…
- CVE-2017-7512CRITICALCVSS 9.8EG 9.82017-07-07
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted…
- CVE-2017-8192HIGHCVSS 7.8EG 7.82017-11-22
FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilege may exploit this vulnerability to obtain the operation authority of some specific directory, caus…
- CVE-2017-8196MEDIUMCVSS 4.2EG 4.22017-11-22
FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to perform, thereby querying, modifying, and deleting certain serv…
- CVE-2017-8216MEDIUMCVSS 5.5EG 5.52017-11-22
Warsaw Huawei Smart phones with software of versions earlier than Warsaw-AL00C00B180, versions earlier than Warsaw-TL10C01B180 have a permission control vulnerability. Due to improper authorization on specific processes, an attacker with t…
- CVE-2017-8276HIGHCVSS 7.8EG 7.82019-01-18
Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429,…
- CVE-2017-8633HIGHCVSS 7.5EG 7.52017-08-08
Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege v…
- CVE-2017-8907HIGHCVSS 8.8EG 8.82017-06-14
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the e…
- CVE-2017-9378MEDIUMCVSS 6.5EG 6.52017-06-02
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to c…
- CVE-2017-9453CRITICALCVSS 9.0EG 9.02023-09-05
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
- CVE-2017-9653CRITICALCVSS 9.8EG 9.82017-08-14
An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker is able to gain pr…
- CVE-2017-9855CRITICALCVSS 9.8EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single Grid Guard code can be used on any SMA i…
- CVE-2018-0096MEDIUMCVSS 5.9EG 5.92018-01-18
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to perform a privilege escalation in which one virtual domain user can view and modify anothe…
- CVE-2018-0110HIGHCVSS 8.1EG 8.12018-01-18
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has been disabled via the web application. The vulnerability is due to a design flaw in Cisco W…
- CVE-2018-0269MEDIUMCVSS 4.3EG 4.32018-04-19
A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an …
- CVE-2018-0278MEDIUMCVSS 6.5EG 6.52018-05-02
A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerability is due to improper cross-origin domain protections fo…
- CVE-2018-0337HIGHCVSS 7.8EG 7.82018-06-21
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerability exists because the affected software l…
- CVE-2018-0338HIGHCVSS 7.8EG 7.82018-06-07
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system. The vulnerability exists becaus…
- CVE-2018-0459MEDIUMCVSS 6.5EG 6.52018-10-05
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to ins…
- CVE-2018-0460MEDIUMCVSS 6.5EG 6.52018-10-05
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parame…
- CVE-2018-0803MEDIUMCVSS 4.2EG 4.22018-01-04
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to access information from one domain and inject it into another domain, due to how Microsoft Edge enforces cross-domain polici…
- CVE-2018-1000105MEDIUMCVSS 4.3EG 4.32018-03-13
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configura…
- CVE-2018-1000106MEDIUMCVSS 5.4EG 5.42018-03-13
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modify the Gerrit confi…
- CVE-2018-1000107MEDIUMCVSS 6.5EG 6.52018-03-13
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Comp…
- CVE-2018-1000109MEDIUMCVSS 4.3EG 4.32018-03-13
An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.
- CVE-2018-1000110MEDIUMCVSS 5.3EG 5.32018-03-13
An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nodes and users.
- CVE-2018-1000111MEDIUMCVSS 5.3EG 5.32018-03-13
An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and u…
- CVE-2018-1000112MEDIUMCVSS 5.3EG 5.32018-03-13
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
- CVE-2018-1000114MEDIUMCVSS 4.3EG 4.32018-03-13
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
- CVE-2018-1000152MEDIUMCVSS 6.3EG 6.32018-04-05
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.ja…
- CVE-2018-1000155CRITICALCVSS 9.8EG 9.82018-05-24
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the controller. that can resul…
- CVE-2018-1000197HIGHCVSS 8.1EG 8.12018-06-05
An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.
- CVE-2018-1000412HIGHCVSS 8.8EG 8.82019-01-09
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentia…
- CVE-2018-1000418HIGHCVSS 8.8EG 8.82019-01-09
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attac…
- CVE-2018-1000420MEDIUMCVSS 6.5EG 6.52019-01-09
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.
- CVE-2018-1000805HIGHCVSS 8.8EG 8.82018-10-08
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →