CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,702)
page 123 of 186| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47629 | Hig | 0.46 | 7.1 | 0.00 | Nov 14, 2023 | DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain… | ||
| CVE-2023-36024 | Hig | 0.46 | 7.1 | 0.01 | Nov 10, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2023-5622 | Hig | 0.46 | 7.1 | 0.00 | Oct 26, 2023 | Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file. | ||
| CVE-2023-36721 | Hig | 0.46 | 7.0 | 0.00 | Oct 10, 2023 | Windows Error Reporting Service Elevation of Privilege Vulnerability | ||
| CVE-2023-26062 | Hig | 0.46 | 7.0 | 0.00 | Jun 14, 2023 | A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that… | ||
| CVE-2020-23362 | Hig | 0.46 | 7.1 | 0.01 | May 9, 2023 | Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter. | ||
| CVE-2023-21896 | Hig | 0.46 | 7.0 | 0.00 | Apr 18, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to… | ||
| CVE-2023-28758 | Hig | 0.46 | 7.1 | 0.00 | Mar 23, 2023 | An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files. | ||
| CVE-2023-21542 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2023-21531 | Hig | 0.46 | 7.0 | 0.01 | Jan 10, 2023 | Azure Service Fabric Container Elevation of Privilege Vulnerability | ||
| CVE-2022-4294 | Hig | 0.46 | 7.1 | 0.00 | Jan 10, 2023 | Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an… | ||
| CVE-2022-4687 | Hig | 0.46 | 8.1 | 0.01 | Dec 23, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-42855 | Hig | 0.46 | 7.1 | 0.01 | Dec 15, 2022 | A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements. | ||
| CVE-2022-31166 | Hig | 0.46 | 8.1 | 0.01 | Sep 7, 2022 | XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. More specifically, editing a right with… | ||
| CVE-2022-30298 | Hig | 0.46 | 7.0 | 0.00 | Sep 6, 2022 | An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root. | ||
| CVE-2022-33646 | Hig | 0.46 | 7.0 | 0.00 | Aug 9, 2022 | Azure Batch Node Agent Elevation of Privilege Vulnerability | ||
| CVE-2022-21827 | Hig | 0.46 | 7.1 | 0.00 | May 26, 2022 | An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as… | ||
| CVE-2022-21699 | Hig | 0.46 | 8.2 | 0.01 | Jan 19, 2022 | IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing… | ||
| CVE-2021-31833 | Hig | 0.46 | 7.1 | 0.00 | Jan 4, 2022 | Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would… | ||
| CVE-2021-39944 | Hig | 0.46 | 7.1 | 0.01 | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to… |
- risk 0.46cvss 7.1epss 0.00
DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain…
- risk 0.46cvss 7.1epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.
- risk 0.46cvss 7.0epss 0.00
Windows Error Reporting Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that…
- risk 0.46cvss 7.1epss 0.01
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.
- risk 0.46cvss 7.0epss 0.00
Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to…
- risk 0.46cvss 7.1epss 0.00
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
- risk 0.46cvss 7.0epss 0.00
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Azure Service Fabric Container Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…
- risk 0.46cvss 8.1epss 0.01
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.46cvss 7.1epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.
- risk 0.46cvss 8.1epss 0.01
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. More specifically, editing a right with…
- risk 0.46cvss 7.0epss 0.00
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
- risk 0.46cvss 7.0epss 0.00
Azure Batch Node Agent Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as…
- risk 0.46cvss 8.2epss 0.01
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing…
- risk 0.46cvss 7.1epss 0.00
Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would…
- risk 0.46cvss 7.1epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…