VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 123 of 186
  • CVE-2023-47629HigNov 14, 2023
    risk 0.46cvss 7.1epss 0.00

    DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create an admin account given certain…

  • CVE-2023-36024HigNov 10, 2023
    risk 0.46cvss 7.1epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-5622HigOct 26, 2023
    risk 0.46cvss 7.1epss 0.00

    Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.

  • CVE-2023-36721HigOct 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Error Reporting Service Elevation of Privilege Vulnerability

  • CVE-2023-26062HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that…

  • CVE-2020-23362HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.01

    Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.

  • CVE-2023-21896HigApr 18, 2023
    risk 0.46cvss 7.0epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to…

  • CVE-2023-28758HigMar 23, 2023
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.

  • CVE-2023-21542HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2023-21531HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.01

    Azure Service Fabric Container Elevation of Privilege Vulnerability

  • CVE-2022-4294HigJan 10, 2023
    risk 0.46cvss 7.1epss 0.00

    Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2022-4687HigDec 23, 2022
    risk 0.46cvss 8.1epss 0.01

    Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2022-42855HigDec 15, 2022
    risk 0.46cvss 7.1epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.

  • CVE-2022-31166HigSep 7, 2022
    risk 0.46cvss 8.1epss 0.01

    XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. More specifically, editing a right with…

  • CVE-2022-30298HigSep 6, 2022
    risk 0.46cvss 7.0epss 0.00

    An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.

  • CVE-2022-33646HigAug 9, 2022
    risk 0.46cvss 7.0epss 0.00

    Azure Batch Node Agent Elevation of Privilege Vulnerability

  • CVE-2022-21827HigMay 26, 2022
    risk 0.46cvss 7.1epss 0.00

    An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as…

  • CVE-2022-21699HigJan 19, 2022
    risk 0.46cvss 8.2epss 0.01

    IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing…

  • CVE-2021-31833HigJan 4, 2022
    risk 0.46cvss 7.1epss 0.00

    Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would…

  • CVE-2021-39944HigDec 13, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…