Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and e
A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p
A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to c
Certain NETGEAR devices are affected by lack of access control at the function level. This affects FS728TLP before 1.0.1
IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth d
In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This
In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE
In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in
In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version che
In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privileg
In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This c
In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validati
In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to
In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to
<p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly han
In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boun
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users wit
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users wit
In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could
In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configura
In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to
In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead
In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to l
In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local info
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat
In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no
In core networking, there is a missing permission check. This could lead to local information disclosure of app network
In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local infor
In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local informatio
In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installat
In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. Thi
In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to
In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This a
In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissi
In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a mis
In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information di
In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing perm
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned in
The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (version
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data
A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read perm
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started