VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 94 of 164
  • CVE-2022-23921HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.00

    Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already…

  • CVE-2021-43828HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/<tmp_file> In that, owner_id…

  • CVE-2021-42291HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.03

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2021-42282HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.03

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2021-31350HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root, leading to…

  • CVE-2021-28702HigOct 6, 2021
    risk 0.49cvss 7.6epss 0.00

    PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is…

  • CVE-2021-29802HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

  • CVE-2021-25442HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.

  • CVE-2020-7467HigMar 26, 2021
    risk 0.49cvss 7.6epss 0.00

    In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a number of AMD virtualization instructions operate on host physical addresses, are not subject to nested page table translation, and…

  • CVE-2021-3283HigFeb 1, 2021
    risk 0.49cvss 7.5epss 0.01

    HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.

  • CVE-2021-1694HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.03

    Windows Update Stack Elevation of Privilege Vulnerability

  • CVE-2020-8258HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.

  • CVE-2020-7335HigDec 1, 2020
    risk 0.49cvss 7.5epss 0.00

    Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link. This exploits a lack of protection through a timing…

  • CVE-2020-2022HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.01

    An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. This vulnerability…

  • CVE-2020-7330HigOct 14, 2020
    risk 0.49cvss 7.5epss 0.00

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call malicious software to execute with elevated privileges via editing of environment variables

  • CVE-2020-9733HigSep 10, 2020
    risk 0.49cvss 7.5epss 0.04

    An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.

  • CVE-2020-14215HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.

  • CVE-2020-7283HigJul 3, 2020
    risk 0.49cvss 7.5epss 0.01

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on…

  • CVE-2020-7281HigJul 3, 2020
    risk 0.49cvss 7.5epss 0.00

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through…

  • CVE-2019-20886HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.