VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 147 of 164
  • CVE-2023-23430LowDec 29, 2023
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-23428LowDec 29, 2023
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-29066LowNov 28, 2023
    risk 0.21cvss 3.2epss 0.00

    The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.

  • CVE-2023-43664MedSep 28, 2023
    risk 0.21cvss 4.3epss 0.00

    PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue has been addressed in commit…

  • CVE-2022-39202MedSep 13, 2022
    risk 0.21cvss 4.3epss 0.01

    matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc…

  • CVE-2022-1003LowMar 18, 2022
    risk 0.21cvss 3.3epss 0.01

    One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

  • CVE-2022-0338MedJan 25, 2022
    risk 0.21cvss 4.3epss 0.01

    Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.

  • CVE-2021-25377LowApr 9, 2021
    risk 0.21cvss 3.3epss 0.00

    Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.

  • CVE-2020-16126LowNov 11, 2020
    risk 0.21cvss 3.3epss 0.01

    An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.

  • CVE-2012-2148LowDec 6, 2019
    risk 0.21cvss 3.3epss 0.00

    An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies

  • CVE-2019-4465LowDec 3, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 163774.

  • CVE-2019-15332LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the…

  • CVE-2019-4112LowSep 30, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.

  • CVE-2019-6997MedSep 9, 2019
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view…

  • CVE-2019-6996MedSep 9, 2019
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers…

  • CVE-2019-6794MedSep 9, 2019
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.

  • CVE-2019-6789MedSep 9, 2019
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For…

  • CVE-2019-4177LowJun 17, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.

  • CVE-2019-4174LowJun 17, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879.

  • CVE-2019-4218LowJun 6, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 159227.