Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-03-09 CVE-2021-21484 Incorrect Authorization vulnerability in SAP Hana 2.0
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.
network
low complexity
sap CWE-863
critical
9.8
2021-03-09 CVE-2021-21481 Incorrect Authorization vulnerability in SAP Netweaver
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check.
low complexity
sap CWE-863
8.8
2021-03-08 CVE-2021-22134 Incorrect Authorization vulnerability in multiple products
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used.
network
low complexity
elastic oracle CWE-863
4.3
2021-03-08 CVE-2021-21362 Incorrect Authorization vulnerability in Minio
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service.
network
low complexity
minio CWE-863
6.5
2021-03-05 CVE-2020-29020 Incorrect Authorization vulnerability in Secomea Sitemanager Firmware
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials.
network
low complexity
secomea CWE-863
7.2
2021-03-05 CVE-2021-27099 Incorrect Authorization vulnerability in Cncf Spire
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker controls the value of an EC2 tag prior to attestation, and the attestor is configured for agent ID templating where the tag value is the last element in the path.
network
high complexity
cncf CWE-863
6.8
2021-03-05 CVE-2021-26964 Incorrect Authorization vulnerability in Arubanetworks Airwave
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-863
7.1
2021-03-05 CVE-2021-21725 Incorrect Authorization vulnerability in ZTE Zxhn H196Q Firmware 9.1.0C2
A ZTE product has an information leak vulnerability.
low complexity
zte CWE-863
5.7
2021-03-04 CVE-2021-26027 Incorrect Authorization vulnerability in Joomla Joomla!
An issue was discovered in Joomla! 3.0.0 through 3.9.24.
network
low complexity
joomla CWE-863
5.3
2021-03-01 CVE-2021-27225 Incorrect Authorization vulnerability in Dataiku Data Science Studio
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
network
low complexity
dataiku CWE-863
5.4