Vulnerabilities > Improper Authorization

DATE CVE VULNERABILITY TITLE RISK
2019-04-03 CVE-2015-5463 Improper Authorization vulnerability in Axiomsl Axiom 9.5.3
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers to (1) access data of other basic users through arbitrary SQL commands, (2) perform a horizontal and vertical privilege escalation, (3) cause a Denial of Service on global application, or (4) write/read/delete arbitrary files on server hosting the application.
network
low complexity
axiomsl CWE-285
critical
9.8
2019-03-25 CVE-2015-3954 Improper Authorization vulnerability in Pifzer products
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default.
network
low complexity
pifzer CWE-285
critical
9.8
2018-10-29 CVE-2016-10734 Improper Authorization vulnerability in Projectsend 582
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
network
low complexity
projectsend CWE-285
critical
9.8
2018-09-10 CVE-2016-7035 Improper Authorization vulnerability in multiple products
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface.
local
low complexity
clusterlabs redhat CWE-285
7.8
2018-09-10 CVE-2016-7071 Improper Authorization vulnerability in Redhat Cloudforms and Cloudforms Management Engine
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users.
network
low complexity
redhat CWE-285
8.8
2018-08-30 CVE-2016-0373 Improper Authorization vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data.
network
low complexity
ibm CWE-285
4.3
2018-08-28 CVE-2014-6049 Improper Authorization vulnerability in PHPmyfaq
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
network
low complexity
phpmyfaq CWE-285
2.7
2018-04-24 CVE-2013-7245 Improper Authorization vulnerability in Sybase Adaptive Server Enterprise 15.7
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859.
network
low complexity
sybase CWE-285
7.5
2018-03-15 CVE-2015-7463 Improper Authorization vulnerability in IBM Business Process Manager
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks.
network
low complexity
ibm CWE-285
4.3
2018-03-13 CVE-2016-9575 Improper Authorization vulnerability in Freeipa
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command.
network
low complexity
freeipa CWE-285
6.3