CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 126 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33393 | Med | 0.40 | 6.2 | 0.00 | May 1, 2024 | An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component. | ||
| CVE-2024-21034 | Med | 0.40 | 6.1 | 0.00 | Apr 16, 2024 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | ||
| CVE-2023-52543 | Med | 0.40 | 6.2 | 0.00 | Apr 8, 2024 | Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-31005 | Med | 0.40 | 6.2 | 0.00 | Feb 3, 2024 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force… | ||
| CVE-2023-6507 | Med | 0.40 | 6.1 | 0.01 | Dec 8, 2023 | An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not… | ||
| CVE-2023-30713 | Med | 0.40 | 6.2 | 0.00 | Sep 6, 2023 | Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock. | ||
| CVE-2023-30642 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function. | ||
| CVE-2023-21513 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition. | ||
| CVE-2023-21458 | Med | 0.40 | 6.2 | 0.00 | Mar 16, 2023 | Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent. | ||
| CVE-2022-48365 | Hig | 0.40 | 7.2 | 0.01 | Mar 12, 2023 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges. | ||
| CVE-2022-24072 | Med | 0.40 | 6.1 | 0.01 | Mar 17, 2022 | The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool. | ||
| CVE-2022-21970 | Med | 0.40 | 6.1 | 0.03 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2021-43835 | Hig | 0.40 | 7.2 | 0.01 | Dec 15, 2021 | Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API it was possible for them to give themselves permissions to areas… | ||
| CVE-2021-33697 | Med | 0.40 | 6.1 | 0.01 | Sep 15, 2021 | Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. | ||
| CVE-2021-31961 | Med | 0.40 | 6.1 | 0.01 | Jul 14, 2021 | Windows InstallService Elevation of Privilege Vulnerability | ||
| CVE-2020-28014 | Med | 0.40 | 6.1 | 0.01 | May 6, 2021 | Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service because root-owned files can be overwritten. | ||
| CVE-2020-7324 | Med | 0.40 | 6.1 | 0.00 | Sep 9, 2020 | Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny access to the SYSTEM folder via incorrectly applied permissions. | ||
| CVE-2019-18899 | Med | 0.40 | 6.2 | 0.00 | Jan 23, 2020 | The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to… | ||
| CVE-2012-4767 | Med | 0.40 | 6.1 | 0.00 | Jan 13, 2020 | An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a malicious user decrypt and potentially change the Safend security policies applied to the machine. | ||
| CVE-2013-2012 | Hig | 0.40 | 7.3 | 0.00 | Oct 31, 2019 | autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. |
- risk 0.40cvss 6.2epss 0.00
An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
- risk 0.40cvss 6.1epss 0.00
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
- risk 0.40cvss 6.2epss 0.00
Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force…
- risk 0.40cvss 6.1epss 0.01
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not…
- risk 0.40cvss 6.2epss 0.00
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
- risk 0.40cvss 6.2epss 0.00
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
- risk 0.40cvss 6.1epss 0.00
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
- risk 0.40cvss 6.2epss 0.00
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
- risk 0.40cvss 7.2epss 0.01
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.
- risk 0.40cvss 6.1epss 0.01
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
- risk 0.40cvss 6.1epss 0.03
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.40cvss 7.2epss 0.01
Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API it was possible for them to give themselves permissions to areas…
- risk 0.40cvss 6.1epss 0.01
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
- risk 0.40cvss 6.1epss 0.01
Windows InstallService Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.01
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service because root-owned files can be overwritten.
- risk 0.40cvss 6.1epss 0.00
Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny access to the SYSTEM folder via incorrectly applied permissions.
- risk 0.40cvss 6.2epss 0.00
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to…
- risk 0.40cvss 6.1epss 0.00
An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a malicious user decrypt and potentially change the Safend security policies applied to the machine.
- risk 0.40cvss 7.3epss 0.00
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.