VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 97 of 164
  • CVE-2017-20025HigJun 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Flash Memory. The manipulation leads to privilege escalation. The attack can be launched remotely.…

  • CVE-2016-15002HigJun 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack…

  • CVE-2021-36945HigAug 12, 2021
    risk 0.48cvss 7.3epss 0.02

    Windows 10 Update Assistant Elevation of Privilege Vulnerability

  • CVE-2020-4184HigMar 15, 2021
    risk 0.48cvss 7.3epss 0.01

    IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 174802..

  • CVE-2021-1706HigJan 12, 2021
    risk 0.48cvss 7.3epss 0.02

    Windows LUAFV Elevation of Privilege Vulnerability

  • CVE-2021-1704HigJan 12, 2021
    risk 0.48cvss 7.3epss 0.01

    Windows Hyper-V Elevation of Privilege Vulnerability

  • CVE-2021-1685HigJan 12, 2021
    risk 0.48cvss 7.3epss 0.01

    Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

  • CVE-2020-17103HigDec 10, 2020
    risk 0.48cvss 7.0epss 0.27

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

  • CVE-2016-9928HigFeb 6, 2020
    risk 0.48cvss 7.4epss 0.05

    MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

  • CVE-2018-11767HigMar 21, 2019
    risk 0.48cvss 7.4epss 0.04

    In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.

  • CVE-2017-6924HigJan 15, 2019
    risk 0.48cvss 7.4epss 0.02

    In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest)…

  • CVE-2018-1000028HigFeb 9, 2018
    risk 0.48cvss 7.4epss 0.01

    Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be…

  • CVE-2017-10104HigAug 8, 2017
    risk 0.48cvss 7.4epss 0.01

    Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP…

  • CVE-2017-7918MedJun 21, 2017
    risk 0.48cvss 6.8epss 0.07

    An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups using specific MIBs. These backups lack proper access control and may allow…

  • CVE-2026-68752HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    A Project Resource Manager may gain broader administrative privileges under specific conditions.

  • CVE-2026-68821HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-14237HigAug 10, 2026
    risk 0.47cvss 7.2epss 0.00

    The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an…

  • CVE-2026-61336HigJul 21, 2026
    risk 0.47cvss 7.2epss 0.00

    Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP…

  • CVE-2026-61094HigJul 21, 2026
    risk 0.47cvss 7.2epss 0.00

    Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable…

  • CVE-2026-60925HigJul 21, 2026
    risk 0.47cvss 7.2epss 0.00

    Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…