VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 129 of 164
  • CVE-2024-33500MedJun 11, 2024
    risk 0.38cvss 5.9epss 0.00

    A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow…

  • CVE-2024-3470MedApr 19, 2024
    risk 0.38cvss 5.9epss 0.01

    An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an organization ruleset. An attacker would require access to a valid deploy key for a repository in the…

  • CVE-2021-37937MedNov 22, 2023
    risk 0.38cvss 5.9epss 0.01

    An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server…

  • CVE-2023-43018MedNov 3, 2023
    risk 0.38cvss 5.9epss 0.00

    IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163.

  • CVE-2022-43927MedFeb 17, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.

  • CVE-2023-21421MedFeb 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.

  • CVE-2022-4041MedJan 31, 2023
    risk 0.38cvss 5.9epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.1.

  • CVE-2022-36861MedSep 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

  • CVE-2022-30735MedJun 7, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.

  • CVE-2021-39937MedDec 13, 2021
    risk 0.38cvss 5.9epss 0.01

    A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

  • CVE-2021-25365MedApr 9, 2021
    risk 0.38cvss 5.9epss 0.00

    An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.

  • CVE-2018-14825MedSep 24, 2018
    risk 0.38cvss 5.8epss 0.01

    On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running Android OS 6.0, D75e running Android OS 6.0, CT50 running…

  • CVE-2016-10613MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2016-10597MedJun 1, 2018
    risk 0.38cvss 5.9epss 0.01

    cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

  • CVE-2017-10046MedAug 8, 2017
    risk 0.38cvss 5.4epss 0.04

    Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. Easily exploitable vulnerability allows low privileged…

  • CVE-2017-6507MedMar 24, 2017
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by…

  • CVE-2026-48210MedMay 31, 2026
    risk 0.37cvss 5.7epss 0.00

    An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the…

  • CVE-2026-39961MedApr 9, 2026
    risk 0.37cvss 6.8epss 0.00

    Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace — production database…

  • CVE-2025-69257MedDec 30, 2025
    risk 0.37cvss 6.7epss 0.00

    theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loads custom Python rules and configuration files from user-writable locations (e.g., `~/.config/theshit/`) without validating…

  • CVE-2024-51521MedNov 5, 2024
    risk 0.37cvss 5.7epss 0.00

    Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.