Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-06-22 CVE-2020-14944 Missing Authorization vulnerability in Globalradar BSA Radar 1.6.7234.24750
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions.
network
low complexity
globalradar CWE-862
7.5
2020-06-19 CVE-2018-21257 Missing Authorization vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.1.
5.0
2020-06-19 CVE-2018-21251 Missing Authorization vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.2 and 5.1.1.
7.5
2020-06-19 CVE-2020-14457 Missing Authorization vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.20.0.
network
low complexity
mattermost CWE-862
5.0
2020-06-18 CVE-2020-3245 Missing Authorization vulnerability in Cisco Smart Software Manager On-Prem 7201910/7202001
A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to create arbitrary user accounts.
network
low complexity
cisco CWE-862
5.0
2020-06-17 CVE-2020-11911 Missing Authorization vulnerability in Treck Tcp/Ip
The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.
network
low complexity
treck CWE-862
5.0
2020-06-16 CVE-2020-14214 Missing Authorization vulnerability in Zammad
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions.
network
zammad CWE-862
5.8
2020-06-16 CVE-2020-14213 Missing Authorization vulnerability in Zammad
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
network
low complexity
zammad CWE-862
5.5
2020-06-11 CVE-2020-0202 Missing Authorization vulnerability in Google Android 11.0
In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-06-11 CVE-2020-0137 Missing Authorization vulnerability in Google Android 10.0
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check.
local
low complexity
google CWE-862
4.6