Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-05-28 CVE-2020-1729 Incorrect Authorization vulnerability in Redhat Smallrye Config
A flaw was found in SmallRye's API through version 1.6.1.
local
low complexity
redhat CWE-863
4.4
2021-05-24 CVE-2020-26555 Incorrect Authorization vulnerability in multiple products
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
5.4
2021-05-24 CVE-2020-26559 Incorrect Authorization vulnerability in Bluetooth Mesh Profile 1.0.0/1.0.1
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device.
low complexity
bluetooth CWE-863
8.8
2021-05-24 CVE-2020-26560 Incorrect Authorization vulnerability in Bluetooth Mesh Profile 1.0.0/1.0.1
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey.
low complexity
bluetooth CWE-863
8.1
2021-05-19 CVE-2021-31158 Incorrect Authorization vulnerability in Couchbase Server
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.
network
low complexity
couchbase CWE-863
6.5
2021-05-14 CVE-2021-20429 Incorrect Authorization vulnerability in IBM Qradar User Behavior Analytics 1.0.0/4.1.0
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy.
network
low complexity
ibm CWE-863
5.3
2021-05-13 CVE-2021-31876 Incorrect Authorization vulnerability in Bitcoin
Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes.
network
low complexity
bitcoin CWE-863
6.5
2021-05-12 CVE-2020-36289 Incorrect Authorization vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint.
network
low complexity
atlassian CWE-863
5.3
2021-05-10 CVE-2021-20538 Incorrect Authorization vulnerability in IBM Cloud PAK for Security 1.5.0.0/1.5.0.1
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms.
network
low complexity
ibm CWE-863
critical
9.1
2021-05-10 CVE-2021-23015 Incorrect Authorization vulnerability in F5 products
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints.
network
low complexity
f5 CWE-863
7.2