Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-01-01 CVE-2016-20004 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
critical
9.8
2021-01-01 CVE-2016-20002 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
critical
9.8
2021-01-01 CVE-2016-20001 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
critical
9.8
2020-12-28 CVE-2020-26029 Incorrect Authorization vulnerability in Zammad
An issue was discovered in Zammad before 3.4.1.
network
low complexity
zammad CWE-863
6.5
2020-12-28 CVE-2020-26028 Incorrect Authorization vulnerability in Zammad
An issue was discovered in Zammad before 3.4.1.
network
low complexity
zammad CWE-863
4.9
2020-12-22 CVE-2020-24674 Incorrect Authorization vulnerability in ABB Symphony + Historian and Symphony + Operations
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected.
network
low complexity
abb CWE-863
8.8
2020-12-21 CVE-2020-4794 Incorrect Authorization vulnerability in IBM products
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking.
network
low complexity
ibm CWE-863
5.4
2020-12-15 CVE-2020-0481 Incorrect Authorization vulnerability in Google Android 11.0
In AndroidManifest.xml, there is a possible permissions bypass.
local
low complexity
google CWE-863
3.3
2020-12-15 CVE-2020-0479 Incorrect Authorization vulnerability in Google Android 11.0
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass.
local
low complexity
google CWE-863
7.8
2020-12-15 CVE-2020-0473 Incorrect Authorization vulnerability in Google Android 11.0
In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass.
low complexity
google CWE-863
4.6