Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management.
The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several paramet
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, con
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to devic
Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions fro
Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 an
In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the f
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee p
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catal
In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check
In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local inf
In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to loca
In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names
In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This cou
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permis
In memory management driver, there is a possible information disclosure due to a missing permission check. This could le
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l
In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to
In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app
In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without
In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missin
In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local i
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier d
In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owne
In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local informa
In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local i
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed,
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617,
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the Syste
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which ca
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_mod
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permissi
A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-le
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before versio
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center befor
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read som
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither o
In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started