Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-5449 Missing Authorization vulnerability in Nextcloud Server
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
network
low complexity
nextcloud CWE-862
4.0
2019-07-25 CVE-2019-10184 Missing Authorization vulnerability in multiple products
undertow before version 2.0.23.Final is vulnerable to an information leak issue.
network
low complexity
redhat netapp CWE-862
5.0
2019-07-23 CVE-2019-11702 Missing Authorization vulnerability in Mozilla Firefox
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted.
4.3
2019-07-23 CVE-2019-11700 Missing Authorization vulnerability in Mozilla Firefox
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted.
4.3
2019-07-18 CVE-2019-1010246 Missing Authorization vulnerability in Mailcleaner
MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure.
network
low complexity
mailcleaner CWE-862
5.0
2019-07-17 CVE-2019-10354 Missing Authorization vulnerability in multiple products
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
network
low complexity
jenkins redhat CWE-862
4.3
2019-07-15 CVE-2019-1010304 Missing Authorization vulnerability in Mirumee Saleor
Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c.
network
low complexity
mirumee CWE-862
5.0
2019-07-11 CVE-2019-10342 Missing Authorization vulnerability in Jenkins Docker
A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2019-07-11 CVE-2019-10341 Missing Authorization vulnerability in Jenkins Docker
A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2019-07-10 CVE-2019-0325 Missing Authorization vulnerability in SAP ERP HCM 3.0
SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll data of employees in a certain area.
network
sap CWE-862
4.9