VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 136 of 186
  • CVE-2024-24778MedMar 3, 2025
    risk 0.42cvss 6.5epss 0.01

    Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixes the issue.

  • CVE-2025-22621MedJan 7, 2025
    risk 0.42cvss 6.4epss 0.00

    In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold…

  • CVE-2024-31141MedNov 19, 2024
    risk 0.42cvss 6.5epss 0.01

    Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these configurations.…

  • CVE-2024-52926MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

  • CVE-2024-8810MedNov 7, 2024
    risk 0.42cvss 6.5epss 0.00

    A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. This vulnerability affected all…

  • CVE-2024-20374MedOct 23, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the…

  • CVE-2024-45919MedOct 7, 2024
    risk 0.42cvss 6.5epss 0.00

    A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in /AssignToMe/SetAction, an attacker can bypass approval workflows leading to unauthorized access to…

  • CVE-2024-6359MedAug 6, 2024
    risk 0.42cvss 6.4epss 0.00

    Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

  • CVE-2024-22278MedAug 2, 2024
    risk 0.42cvss 6.4epss 0.00

    Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configurations.

  • CVE-2024-1575MedJul 23, 2024
    risk 0.42cvss 6.5epss 0.00

    The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.

  • CVE-2024-24970MedJul 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

  • CVE-2024-6325MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advis…

  • CVE-2024-4390MedJun 20, 2024
    risk 0.42cvss 6.5epss 0.01

    The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any…

  • CVE-2024-34517MedMay 7, 2024
    risk 0.42cvss 6.5epss 0.01

    The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

  • CVE-2024-34146MedMay 2, 2024
    risk 0.42cvss 6.5epss 0.01

    Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.

  • CVE-2024-21121MedApr 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2024-20262MedMar 13, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or overwrite files in a system directory, which could lead to a denial of service (DoS) condition. The attacker would require valid…

  • CVE-2024-28197HigMar 11, 2024
    risk 0.42cvss 7.5epss 0.00

    Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZITADEL instance. An attacker could take…

  • CVE-2024-25990MedMar 11, 2024
    risk 0.42cvss 6.4epss 0.00

    In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-30617MedJan 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has gained root privilege of the node that kruise-daemon run can leverage the kruise-daemon pod to list all…