VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 121 of 164
  • CVE-2019-3789MedApr 24, 2019
    risk 0.42cvss 6.5epss 0.01

    Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissions can create a private domain that shadows the external domain of the route…

  • CVE-2019-10676MedApr 8, 2019
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Uniqkey Password Manager 1.14. Upon entering new credentials to a site that is not registered within this product, a pop-up window will appear prompting the user if they want to save this new password. This pop-up window will persist on any page the…

  • CVE-2019-5768MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

  • CVE-2018-18344MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension.

  • CVE-2018-6080MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.01

    Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .

  • CVE-2018-14808MedOct 1, 2018
    risk 0.42cvss 6.5epss 0.01

    Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected products.

  • CVE-2018-14836MedAug 2, 2018
    risk 0.42cvss 6.5epss 0.01

    Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.

  • CVE-2018-12884MedJun 26, 2018
    risk 0.42cvss 6.5epss 0.01

    In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastructure menu.

  • CVE-2017-2672MedJun 21, 2018
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

  • CVE-2018-1495MedMay 29, 2018
    risk 0.42cvss 6.5epss 0.02

    IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a denial of service. IBM X-Force ID: 141148.

  • CVE-2018-1134MedMay 25, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL.

  • CVE-2017-10690MedFeb 9, 2018
    risk 0.42cvss 6.5epss 0.01

    In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4

  • CVE-2018-0010MedJan 10, 2018
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not have SSH access to a device to reuse the URL that was created for another user to perform SSH access. Affected releases are all versions of Junos Space Security Director prior to…

  • CVE-2017-1000156MedNov 3, 2017
    risk 0.42cvss 6.5epss 0.01

    Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

  • CVE-2017-15917MedOct 26, 2017
    risk 0.42cvss 6.5epss 0.01

    In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.

  • CVE-2017-1000104MedOct 5, 2017
    risk 0.42cvss 6.5epss 0.01

    The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now…

  • CVE-2017-8447MedSep 29, 2017
    risk 0.42cvss 6.5epss 0.01

    An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.

  • CVE-2017-12422MedAug 29, 2017
    risk 0.42cvss 6.5epss 0.02

    NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors.

  • CVE-2017-10103MedAug 8, 2017
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with…

  • CVE-2017-7916MedAug 7, 2017
    risk 0.42cvss 6.5epss 0.01

    A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A…