VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 61 of 79
  • CVE-2024-8037MedOct 2, 2024
    risk 0.35cvss 6.5epss 0.00

    Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are…

  • CVE-2024-21122MedJul 16, 2024
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2023-38335MedJul 20, 2023
    risk 0.35cvss 5.3epss 0.01

    Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio…

  • CVE-2023-29923MedApr 19, 2023
    risk 0.35cvss 5.3epss 0.10

    PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.

  • CVE-2022-46774MedMar 15, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.

  • CVE-2022-3758MedMar 9, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a…

  • CVE-2022-45383MedNov 15, 2022
    risk 0.35cvss 6.5epss 0.01

    An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.

  • CVE-2022-42128MedNov 15, 2022
    risk 0.35cvss 5.3epss 0.01

    The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.

  • CVE-2022-42127MedNov 15, 2022
    risk 0.35cvss 5.3epss 0.01

    The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.

  • CVE-2022-27960MedApr 10, 2022
    risk 0.35cvss 5.4epss 0.00

    Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.

  • CVE-2022-27958MedApr 10, 2022
    risk 0.35cvss 5.4epss 0.01

    Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers to access and arbitrarily modify users' personal information.

  • CVE-2021-38268MedMar 2, 2022
    risk 0.35cvss 6.5epss 0.01

    The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users…

  • CVE-2022-22296MedJan 24, 2022
    risk 0.35cvss 5.3epss 0.01

    Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed.

  • CVE-2021-43199MedNov 9, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

  • CVE-2021-37351MedAug 13, 2021
    risk 0.35cvss 5.3epss 0.03

    Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.

  • CVE-2020-13667MedMay 17, 2021
    risk 0.35cvss 5.3epss 0.01

    Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker might be…

  • CVE-2021-20653MedFeb 17, 2021
    risk 0.35cvss 5.3epss 0.01

    Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote attackers to bypass access restriction and to obtain unauthorized historical data without access privileges via unspecified vectors.

  • CVE-2020-29582MedFeb 3, 2021
    risk 0.35cvss 5.3epss 0.03

    In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

  • CVE-2020-25208MedFeb 3, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.

  • CVE-2020-13922MedJan 11, 2021
    risk 0.35cvss 6.5epss 0.02

    Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.