Total
4572 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-32112 | 1 Sap | 2 S4core, Vendor Master Hierarchy | 2023-05-15 | N/A | 5.5 MEDIUM |
Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system. | |||||
CVE-2022-38685 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2023-05-12 | N/A | 5.5 MEDIUM |
In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed. | |||||
CVE-2023-2590 | 1 Answer | 1 Answer | 2023-05-12 | N/A | 3.5 LOW |
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9. | |||||
CVE-2023-22728 | 1 Silverstripe | 1 Framework | 2023-05-04 | N/A | 4.3 MEDIUM |
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue. | |||||
CVE-2023-2193 | 1 Mattermost | 1 Mattermost | 2023-05-02 | N/A | 9.1 CRITICAL |
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token. | |||||
CVE-2023-25552 | 1 Schneider-electric | 1 Struxureware Data Center Expert | 2023-04-27 | N/A | 8.1 HIGH |
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) | |||||
CVE-2012-6614 | 1 Dlink | 2 Dsr-250n, Dsr-250n Firmware | 2023-04-26 | 9.0 HIGH | 7.2 HIGH |
D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password. | |||||
CVE-2023-1903 | 1 Sap | 1 Hcm Fiori App My Forms | 2023-04-18 | N/A | 4.3 MEDIUM |
SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data. | |||||
CVE-2023-1782 | 1 Hashicorp | 1 Nomad | 2023-04-12 | N/A | 9.8 CRITICAL |
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3. | |||||
CVE-2023-23854 | 1 Sap | 1 Netweaver Application Server Abap | 2023-04-11 | N/A | 5.4 MEDIUM |
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |||||
CVE-2023-24528 | 1 Sap | 1 Fiori | 2023-04-11 | N/A | 6.5 MEDIUM |
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents. | |||||
CVE-2023-24524 | 1 Sap | 1 S\/4hana | 2023-04-11 | N/A | 6.5 MEDIUM |
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability. | |||||
CVE-2022-31765 | 1 Siemens | 372 6ag1206-2bb00-7ac2, 6ag1206-2bb00-7ac2 Firmware, 6ag1206-2bs00-7ac2 and 369 more | 2023-04-11 | N/A | 8.8 HIGH |
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges. | |||||
CVE-2023-28673 | 1 Jenkins | 1 Octoperf Load Testing | 2023-04-08 | N/A | 4.3 MEDIUM |
A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
CVE-2022-47462 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2023-03-23 | N/A | 6.7 MEDIUM |
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. | |||||
CVE-2022-47461 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2023-03-23 | N/A | 6.7 MEDIUM |
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. | |||||
CVE-2023-27462 | 1 Siemens | 1 Ruggedcom Crossbow | 2023-03-17 | N/A | 4.3 MEDIUM |
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to access data they are not authorized for. | |||||
CVE-2023-27310 | 1 Siemens | 1 Ruggedcom Crossbow | 2023-03-17 | N/A | 8.8 HIGH |
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts. | |||||
CVE-2023-27309 | 1 Siemens | 1 Ruggedcom Crossbow | 2023-03-17 | N/A | 8.8 HIGH |
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions. | |||||
CVE-2022-47484 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2023-03-16 | N/A | 5.5 MEDIUM |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. |