Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-01-27 CVE-2020-4816 Missing Authorization vulnerability in IBM Cloud PAK for Security 1.4.0.0
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-862
5.9
2021-01-18 CVE-2020-7343 Missing Authorization vulnerability in Mcafee Agent
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files.
local
low complexity
mcafee CWE-862
5.5
2021-01-14 CVE-2020-27220 Missing Authorization vulnerability in Eclipse Hono
The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device.
network
low complexity
eclipse CWE-862
8.8
2021-01-13 CVE-2020-9209 Missing Authorization vulnerability in Huawei Smc2.0 Firmware
There is a privilege escalation vulnerability in SMC2.0 product.
local
low complexity
huawei CWE-862
6.7
2021-01-13 CVE-2021-1143 Missing Authorization vulnerability in Cisco Connected Mobile Experiences 10.6.0/10.6.1/10.6.2
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system.
network
low complexity
cisco CWE-862
4.3
2021-01-12 CVE-2021-23123 Missing Authorization vulnerability in Joomla Joomla!
An issue was discovered in Joomla! 3.0.0 through 3.9.23.
network
low complexity
joomla CWE-862
5.3
2021-01-12 CVE-2021-21468 Missing Authorization vulnerability in SAP Business Warehouse
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
network
low complexity
sap CWE-862
6.5
2021-01-12 CVE-2021-21467 Missing Authorization vulnerability in SAP Banking Services
SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
4.3
2021-01-08 CVE-2020-5022 Missing Authorization vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access.
network
low complexity
ibm CWE-862
5.3
2021-01-08 CVE-2020-16029 Missing Authorization vulnerability in Google Chrome
Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file.
network
low complexity
google CWE-862
8.8