VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 120 of 164
  • CVE-2020-8223MedOct 5, 2020
    risk 0.42cvss 6.5epss 0.01

    A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

  • CVE-2020-14201MedAug 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

  • CVE-2020-7019MedAug 18, 2020
    risk 0.42cvss 6.5epss 0.01

    In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could…

  • CVE-2020-8320MedJun 9, 2020
    risk 0.42cvss 6.4epss 0.00

    An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.

  • CVE-2020-7916MedMar 16, 2020
    risk 0.42cvss 6.5epss 0.01

    be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any…

  • CVE-2020-5182MedFeb 3, 2020
    risk 0.42cvss 6.5epss 0.01

    The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer), the tabnabbing may occur.…

  • CVE-2018-8654MedJan 24, 2020
    risk 0.42cvss 6.5epss 0.02

    An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'.

  • CVE-2018-16271MedJan 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the…

  • CVE-2018-16265MedJan 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung…

  • CVE-2015-5072MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.02

    The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary local files via the __imageid parameter.

  • CVE-2015-5071MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.02

    AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary files via the __report parameter of the BIRT viewer servlet.

  • CVE-2019-5259MedDec 16, 2019
    risk 0.42cvss 6.5epss 0.01

    There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600). An attacker with low permissions can view some high-privilege information by running specific commands.Successful…

  • CVE-2019-19783MedDec 16, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a…

  • CVE-2019-13738MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2013-2625MedNov 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified

  • CVE-2019-14220MedSep 24, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call.…

  • CVE-2016-11011MedSep 20, 2019
    risk 0.42cvss 6.5epss 0.01

    The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

  • CVE-2019-4477MedSep 17, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line options. IBM X-Force ID: 163997.

  • CVE-2019-7278MedJul 1, 2019
    risk 0.42cvss 6.5epss 0.02

    Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.

  • CVE-2019-6617MedMay 3, 2019
    risk 0.42cvss 6.5epss 0.02

    On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc/passwd) using SFTP to modify user permissions, without Advanced Shell access.…