VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 417 of 668
  • CVE-2022-39291MedOct 7, 2022
    risk 0.32cvss 5.4epss 0.05

    ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder. This was observed through an…

  • CVE-2022-20913MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with…

  • CVE-2022-32253MedJun 14, 2022
    risk 0.32cvss 4.9epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker.

  • CVE-2021-37586MedAug 13, 2021
    risk 0.32cvss 4.9epss 0.01

    The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Administrator rights) to replay a previously recorded conversation of another tenant due to insufficient validation.

  • CVE-2021-20496MedJul 15, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966.

  • CVE-2021-20583MedJun 25, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation.. IBM X-Force ID: 199396.

  • CVE-2021-0134MedJun 9, 2021
    risk 0.32cvss 4.9epss 0.01

    Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to potentially enable denial of service via network access.

  • CVE-2021-27617MedMay 11, 2021
    risk 0.32cvss 4.9epss 0.01

    The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application,…

  • CVE-2021-29425MedApr 13, 2021
    risk 0.32cvss 4.8epss 0.10

    In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus…

  • CVE-2018-25004MedMar 1, 2021
    risk 0.32cvss 4.9epss 0.01

    A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

  • CVE-2021-23835MedJan 15, 2021
    risk 0.32cvss 4.9epss 0.02

    An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the…

  • CVE-2020-27727MedDec 24, 2020
    risk 0.32cvss 4.9epss 0.01

    On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently validate user input, allowing the user read access to the…

  • CVE-2020-8255MedOct 28, 2020
    risk 0.32cvss 4.9epss 0.02

    A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.

  • CVE-2020-4618MedSep 22, 2020
    risk 0.32cvss 4.9epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input validation. IBM X-Force ID: 184937.

  • CVE-2020-0537MedJun 15, 2020
    risk 0.32cvss 4.9epss 0.02

    Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.

  • CVE-2019-15624MedFeb 4, 2020
    risk 0.32cvss 4.9epss 0.01

    Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

  • CVE-2020-8095MedJan 30, 2020
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial of service on the affected device.

  • CVE-2019-6529MedJan 7, 2020
    risk 0.32cvss 4.9epss 0.01

    An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166).

  • CVE-2011-4968MedNov 19, 2019
    risk 0.32cvss 4.8epss 0.04

    nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

  • CVE-2019-5976MedSep 12, 2019
    risk 0.32cvss 4.9epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via unspecified vectors.