Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-06-11 CVE-2020-13850 Missing Authorization vulnerability in Pandorafms Pandora FMS 7.44
Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
network
low complexity
pandorafms CWE-862
5.0
2020-06-10 CVE-2020-5362 Missing Authorization vulnerability in Dell products
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.
local
low complexity
dell CWE-862
2.1
2020-06-10 CVE-2020-13270 Missing Authorization vulnerability in Gitlab
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API
network
low complexity
gitlab CWE-862
6.5
2020-06-10 CVE-2020-6270 Missing Authorization vulnerability in SAP Netweaver Application Server Abap
SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.
network
low complexity
sap CWE-862
6.5
2020-06-10 CVE-2020-6268 Missing Authorization vulnerability in SAP ERP (Ea-Finserv) and ERP (S4Core)
Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to Missing Authorization Check.
network
low complexity
sap CWE-862
5.5
2020-06-09 CVE-2020-13266 Missing Authorization vulnerability in Gitlab
Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
network
low complexity
gitlab CWE-862
4.0
2020-06-03 CVE-2020-1963 Missing Authorization vulnerability in Apache Ignite
Apache Ignite uses H2 database to build SQL distributed execution engine.
network
low complexity
apache CWE-862
critical
9.1
2020-05-23 CVE-2020-13425 Missing Authorization vulnerability in Thetrackr Trackr Firmware 20200506
TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.
low complexity
thetrackr CWE-862
6.8
2020-05-18 CVE-2020-13144 Missing Authorization vulnerability in EDX Open EDX Platform 2.5
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code.
network
low complexity
edx CWE-862
6.5
2020-05-18 CVE-2019-20801 Missing Authorization vulnerability in Readdle Documents
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS.
network
low complexity
readdle CWE-862
5.0