VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 68 of 79
  • CVE-2018-2025MedNov 25, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551.

  • CVE-2013-1425MedNov 7, 2019
    risk 0.29cvss 5.5epss 0.00

    ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.

  • CVE-2019-15962MedOct 16, 2019
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attacker could exploit…

  • CVE-2019-16355MedSep 16, 2019
    risk 0.29cvss 5.5epss 0.00

    The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.

  • CVE-2013-0266MedMar 8, 2013
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading…

  • CVE-2026-0748MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses…

  • CVE-2025-15335MedFeb 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an information disclosure vulnerability in Threat Response.

  • CVE-2025-15334MedFeb 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an information disclosure vulnerability in Threat Response.

  • CVE-2025-15333MedFeb 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an information disclosure vulnerability in Threat Response.

  • CVE-2025-7672MedJul 15, 2025
    risk 0.28cvss 4.3epss 0.00

    The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.

  • CVE-2025-27926MedMar 10, 2025
    risk 0.28cvss 4.3epss 0.00

    In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.

  • CVE-2024-47593MedNov 12, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was…

  • CVE-2024-34661MedSep 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.

  • CVE-2024-34223MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.

  • CVE-2023-42501MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma…

  • CVE-2023-32999MedMay 16, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials.

  • CVE-2023-32996MedMay 16, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails.

  • CVE-2023-1229MedMar 7, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-23850MedFeb 15, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-23848MedFeb 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…