Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 180/188
6.5
CVE-2019-11784

Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and e

6.4
CVE-2020-10689

A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An

6.4
CVE-2020-5345

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p

6.1
CVE-2020-10746

A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to c

6.0
CVE-2019-20676

Certain NETGEAR devices are affected by lack of access control at the function level. This affects FS728TLP before 1.0.1

5.9
CVE-2020-4413

IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to

5.9
CVE-2020-4175

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur

5.9
CVE-2020-4783

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by

5.9
CVE-2020-4841

IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to

5.5
CVE-2020-0023

In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth d

5.5
CVE-2020-0035

In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This

5.5
CVE-2019-15876

In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE

5.5
CVE-2019-15877

In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in

5.5
CVE-2020-0106

In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version che

5.5
CVE-2020-0177

In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privileg

5.5
CVE-2020-0178

In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This c

5.5
CVE-2020-0107

In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validati

5.5
CVE-2020-0239

In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to

5.5
CVE-2020-0250

In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to

5.5
CVE-2020-0989

<p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly han

5.5
CVE-2020-0288

In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boun

5.5
CVE-2020-0289

In PackageManager, there is a missing permission check. This could lead to local information disclosure across users wit

5.5
CVE-2020-0290

In PackageManager, there is a missing permission check. This could lead to local information disclosure across users wit

5.5
CVE-2020-0293

In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could

5.5
CVE-2020-0314

In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configura

5.5
CVE-2020-0317

In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to

5.5
CVE-2020-0343

In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead

5.5
CVE-2020-0372

In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to l

5.5
CVE-2020-0265

In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local info

5.5
CVE-2020-0276

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat

5.5
CVE-2020-0284

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat

5.5
CVE-2020-0285

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local informat

5.5
CVE-2020-0316

In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no

5.5
CVE-2020-0327

In core networking, there is a missing permission check. This could lead to local information disclosure of app network

5.5
CVE-2020-0246

In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local infor

5.5
CVE-2020-0378

In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local informatio

5.5
CVE-2020-0419

In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installat

5.5
CVE-2020-0437

In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. Thi

5.5
CVE-2020-0448

In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to

5.5
CVE-2020-0454

In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission

5.5
CVE-2020-27349

Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This a

5.5
CVE-2020-0468

In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissi

5.5
CVE-2020-0477

In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a mis

5.5
CVE-2020-0497

In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information di

5.5
CVE-2020-27032

In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing perm

5.4
CVE-2019-11761

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned in

5.4
CVE-2020-6199

The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and

5.4
CVE-2020-6212

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (version

5.4
CVE-2020-14213

In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data

5.4
CVE-2020-2204

A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read perm

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started