VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 138 of 186
  • CVE-2022-35775MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-2498MedAug 5, 2022
    risk 0.42cvss 6.4epss 0.01

    An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.

  • CVE-2022-34338MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962.

  • CVE-2022-20819MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive…

  • CVE-2017-20021MedJun 9, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version…

  • CVE-2022-29179HigMay 20, 2022
    risk 0.42cvss 7.5epss 0.00

    Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where…

  • CVE-2021-36293MedApr 8, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.

  • CVE-2021-36290MedApr 8, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges.

  • CVE-2022-20782MedApr 6, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege…

  • CVE-2021-45230MedJan 20, 2022
    risk 0.42cvss 6.5epss 0.02

    In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.

  • CVE-2022-0090MedJan 18, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of…

  • CVE-2021-43528MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability…

  • CVE-2021-39192MedSep 3, 2021
    risk 0.42cvss 6.5epss 0.01

    Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege…

  • CVE-2021-29951MedJun 24, 2021
    risk 0.42cvss 6.5epss 0.02

    The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop'…

  • CVE-2021-24158MedApr 5, 2021
    risk 0.42cvss 6.5epss 0.01

    Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden…

  • CVE-2020-12528MedMar 2, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.

  • CVE-2020-12527MedMar 2, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding…

  • CVE-2021-1416MedFeb 17, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sensitive data. An…

  • CVE-2020-35557MedFeb 16, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.

  • CVE-2020-13518MedDec 18, 2020
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c402084 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this…