Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 167/188
5.5
CVE-2021-39742

In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could l

5.5
CVE-2021-39751

In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permissi

5.5
CVE-2021-39753

In DomainVerificationService, there is a possible way to access app domain verification information due to a missing per

5.5
CVE-2022-20011

In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to mi

5.5
CVE-2022-20115

In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information wit

5.5
CVE-2022-20121

In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This co

5.5
CVE-2022-21748

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf

5.5
CVE-2022-21749

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf

5.5
CVE-2022-31752

Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect

5.5
CVE-2022-20172

In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This

5.5
CVE-2022-20200

In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. Thi

5.5
CVE-2022-20206

In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead

5.5
CVE-2022-21763

In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc

5.5
CVE-2022-21764

In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc

5.5
CVE-2022-20225

In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a m

5.5
CVE-2022-20352

In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request lo

5.5
CVE-2021-0735

In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced i

5.5
CVE-2022-20259

In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local info

5.5
CVE-2022-20263

In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could l

5.5
CVE-2022-20284

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf

5.5
CVE-2022-20294

In Content, there is a possible way to learn about an account present on the device due to a missing permission check. T

5.5
CVE-2022-20295

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check

5.5
CVE-2022-20296

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check

5.5
CVE-2022-20298

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check

5.5
CVE-2022-20299

In ContentService, there is a possible way to check if the given account exists on the device due to a missing permissio

5.5
CVE-2022-20300

In Content, there is a possible way to check if the given account exists on the device due to a missing permission check

5.5
CVE-2022-20301

In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This

5.5
CVE-2022-20303

In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission d

5.5
CVE-2022-20312

In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission chec

5.5
CVE-2022-20322

In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead t

5.5
CVE-2022-20323

In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lea

5.5
CVE-2022-20326

In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to lo

5.5
CVE-2022-20341

In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could

5.5
CVE-2022-38677

In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no

5.5
CVE-2022-38679

In music service, there is a missing permission check. This could lead to local denial of service in music service with

5.5
CVE-2022-38687

In messaging service, there is a missing permission check. This could lead to local denial of service in messaging servi

5.5
CVE-2022-38688

In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit

5.5
CVE-2022-38689

In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit

5.5
CVE-2022-38697

In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts ser

5.5
CVE-2022-39103

In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service w

5.5
CVE-2022-39112

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with

5.5
CVE-2022-39113

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with

5.5
CVE-2022-39114

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with

5.5
CVE-2022-39115

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with

5.5
CVE-2022-39117

In messaging service, there is a missing permission check. This could lead to local information disclosure with no addit

5.5
CVE-2022-42766

In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

5.5
CVE-2022-42782

In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

5.5
CVE-2022-20510

In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the n

5.5
CVE-2022-20511

In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead

5.4
CVE-2022-0179

snipe-it is vulnerable to Missing Authorization

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started