VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 118 of 164
  • CVE-2023-28640MedMar 27, 2023
    risk 0.42cvss 6.4epss 0.00

    Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they do not have permission for if they correctly guess the URL, which includes…

  • CVE-2023-23610MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to…

  • CVE-2022-46172MedDec 28, 2022
    risk 0.42cvss 6.4epss 0.01

    authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where…

  • CVE-2022-4264MedDec 9, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

  • CVE-2022-23737MedDec 1, 2022
    risk 0.42cvss 6.5epss 0.01

    An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write…

  • CVE-2022-3419MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.00

    The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

  • CVE-2020-36603MedSep 14, 2022
    risk 0.42cvss 6.5epss 0.00

    The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys…

  • CVE-2022-22483MedSep 13, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.

  • CVE-2022-2568MedAug 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

  • CVE-2022-35782MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-35781MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-35780MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-35775MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-2498MedAug 5, 2022
    risk 0.42cvss 6.4epss 0.01

    An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

  • CVE-2022-34338MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962.

  • CVE-2022-20819MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive…

  • CVE-2017-20021MedJun 9, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version…

  • CVE-2022-29179HigMay 20, 2022
    risk 0.42cvss 7.5epss 0.00

    Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where…

  • CVE-2021-36293MedApr 8, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.

  • CVE-2021-36290MedApr 8, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges.