CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 118 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28640 | Med | 0.42 | 6.4 | 0.00 | Mar 27, 2023 | Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they do not have permission for if they correctly guess the URL, which includes… | ||
| CVE-2023-23610 | Med | 0.42 | 6.5 | 0.01 | Jan 26, 2023 | GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to… | ||
| CVE-2022-46172 | Med | 0.42 | 6.4 | 0.01 | Dec 28, 2022 | authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where… | ||
| CVE-2022-4264 | Med | 0.42 | 6.5 | 0.01 | Dec 9, 2022 | Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration. | ||
| CVE-2022-23737 | Med | 0.42 | 6.5 | 0.01 | Dec 1, 2022 | An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write… | ||
| CVE-2022-3419 | Med | 0.42 | 6.5 | 0.00 | Oct 31, 2022 | The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator | ||
| CVE-2020-36603 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2022 | The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys… | ||
| CVE-2022-22483 | Med | 0.42 | 6.5 | 0.01 | Sep 13, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979. | ||
| CVE-2022-2568 | Med | 0.42 | 6.5 | 0.01 | Aug 18, 2022 | A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges. | ||
| CVE-2022-35782 | Med | 0.42 | 6.5 | 0.02 | Aug 9, 2022 | Azure Site Recovery Elevation of Privilege Vulnerability | ||
| CVE-2022-35781 | Med | 0.42 | 6.5 | 0.02 | Aug 9, 2022 | Azure Site Recovery Elevation of Privilege Vulnerability | ||
| CVE-2022-35780 | Med | 0.42 | 6.5 | 0.02 | Aug 9, 2022 | Azure Site Recovery Elevation of Privilege Vulnerability | ||
| CVE-2022-35775 | Med | 0.42 | 6.5 | 0.02 | Aug 9, 2022 | Azure Site Recovery Elevation of Privilege Vulnerability | ||
| CVE-2022-2498 | Med | 0.42 | 6.4 | 0.01 | Aug 5, 2022 | An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author. | ||
| CVE-2022-34338 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962. | ||
| CVE-2022-20819 | Med | 0.42 | 6.5 | 0.01 | Jun 15, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive… | ||
| CVE-2017-20021 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2022 | A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version… | ||
| CVE-2022-29179 | Hig | 0.42 | 7.5 | 0.00 | May 20, 2022 | Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where… | ||
| CVE-2021-36293 | Med | 0.42 | 6.4 | 0.00 | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges. | ||
| CVE-2021-36290 | Med | 0.42 | 6.4 | 0.00 | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges. |
- risk 0.42cvss 6.4epss 0.00
Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they do not have permission for if they correctly guess the URL, which includes…
- risk 0.42cvss 6.5epss 0.01
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to…
- risk 0.42cvss 6.4epss 0.01
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where…
- risk 0.42cvss 6.5epss 0.01
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
- risk 0.42cvss 6.5epss 0.01
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write…
- risk 0.42cvss 6.5epss 0.00
The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
- risk 0.42cvss 6.5epss 0.00
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys…
- risk 0.42cvss 6.5epss 0.01
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
- risk 0.42cvss 6.5epss 0.01
A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.
- risk 0.42cvss 6.5epss 0.02
Azure Site Recovery Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.02
Azure Site Recovery Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.02
Azure Site Recovery Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.02
Azure Site Recovery Elevation of Privilege Vulnerability
- risk 0.42cvss 6.4epss 0.01
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
- risk 0.42cvss 6.5epss 0.01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive…
- risk 0.42cvss 6.5epss 0.01
A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version…
- risk 0.42cvss 7.5epss 0.00
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where…
- risk 0.42cvss 6.4epss 0.00
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.
- risk 0.42cvss 6.4epss 0.00
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges.