VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 137 of 186
  • CVE-2023-6804MedDec 21, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was…

  • CVE-2023-6119MedNov 16, 2023
    risk 0.42cvss 6.5epss 0.00

    An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to files that usually require a higher privilege level. This is caused by GetSusp not correctly protecting a directory that it…

  • CVE-2023-41966MedOct 26, 2023
    risk 0.42cvss 6.5epss 0.01

    The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.

  • CVE-2023-5214MedOct 6, 2023
    risk 0.42cvss 6.5epss 0.00

    In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

  • CVE-2023-20235MedOct 4, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability…

  • CVE-2023-20266MedAug 30, 2023
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to elevate privileges to…

  • CVE-2023-38187MedJul 21, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-0959MedApr 5, 2023
    risk 0.42cvss 6.5epss 0.01

    Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.

  • CVE-2023-28640MedMar 27, 2023
    risk 0.42cvss 6.4epss 0.00

    Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they do not have permission for if they correctly guess the URL, which includes…

  • CVE-2023-23610MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to…

  • CVE-2022-46172MedDec 28, 2022
    risk 0.42cvss 6.4epss 0.01

    authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where…

  • CVE-2022-4264MedDec 9, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

  • CVE-2022-23737MedDec 1, 2022
    risk 0.42cvss 6.5epss 0.01

    An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write…

  • CVE-2022-3419MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.00

    The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

  • CVE-2020-36603MedSep 14, 2022
    risk 0.42cvss 6.5epss 0.01

    The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys…

  • CVE-2022-22483MedSep 13, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.

  • CVE-2022-2568MedAug 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

  • CVE-2022-35782MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-35781MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-35780MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability