Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,422 CVEs tagged with CWE-863326 Critical, 1,184 High, 1,647 Medium, 262 Low, 3 Unrated.

CVE-2017-16858

Published Jan 31, 2018

The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crow…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15091

Published Jan 23, 2018

An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-12118

Published Jan 19, 2018

An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). An attacker can send JSO…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12116

Published Jan 19, 2018

An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request ca…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12113

Published Jan 19, 2018

An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can c…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12117

Published Jan 19, 2018

An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can caus…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12115

Published Jan 19, 2018

An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request c…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12114

Published Jan 19, 2018

An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can caus…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12112

Published Jan 19, 2018

An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can ca…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0110

Published Jan 18, 2018

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has been disabled via the web appli…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0096

Published Jan 18, 2018

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to perform a privilege escalation…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2361

Published Jan 9, 2018

In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-17067

Published Nov 30, 2017

Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mis…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1628

Published Nov 27, 2017

IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorization checks.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0910

Published Nov 27, 2017

In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8216

Published Nov 22, 2017

Warsaw Huawei Smart phones with software of versions earlier than Warsaw-AL00C00B180, versions earlier than Warsaw-TL10C01B180 have a permission control vulnerability. Due to impr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8196

Published Nov 22, 2017

FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to per…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8192

Published Nov 22, 2017

FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilege may exploit this vulnerability to obt…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 3,351-3,375 of 3,422 CVEsPage 135 of 137