VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 143 of 164
  • CVE-2021-30152MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.

  • CVE-2021-24207MedApr 5, 2021
    risk 0.28cvss 4.3epss 0.01

    By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.

  • CVE-2021-26697MedFeb 17, 2021
    risk 0.28cvss 5.3epss 0.05

    The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and…

  • CVE-2020-8275MedJan 6, 2021
    risk 0.28cvss 4.3epss 0.02

    Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would…

  • CVE-2020-14318MedDec 3, 2020
    risk 0.28cvss 4.3epss 0.02

    A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

  • CVE-2020-26077MedNov 18, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to improper access…

  • CVE-2020-8624MedAug 21, 2020
    risk 0.28cvss 4.3epss 0.04

    In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the…

  • CVE-2015-8032MedAug 14, 2020
    risk 0.28cvss 5.3epss 0.01

    In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

  • CVE-2020-15826MedAug 8, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

  • CVE-2019-4589MedAug 3, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.

  • CVE-2020-11466MedApr 1, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive…

  • CVE-2020-11464MedApr 1, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users registered on the system. This includes their full name, privilege, email address,…

  • CVE-2020-10660MedMar 23, 2020
    risk 0.28cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.

  • CVE-2020-7908MedJan 30, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.

  • CVE-2018-16268MedJan 22, 2020
    risk 0.28cvss 4.3epss 0.01

    The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1,…

  • CVE-2019-3990MedDec 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the…

  • CVE-2019-13705MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

  • CVE-2019-18365MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.

  • CVE-2015-9390MedSep 20, 2019
    risk 0.28cvss 4.3epss 0.01

    The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.

  • CVE-2019-4047MedApr 29, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.