VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (352)

page 7 of 18
  • CVE-2025-43700HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.  This impacts OmniStudio: before Spring 2025.

  • CVE-2025-43697HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025

  • CVE-2024-57698HigApr 29, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access…

  • CVE-2021-3978HigJan 29, 2025
    risk 0.49cvss 7.5epss 0.00

    When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow…

  • CVE-2024-54557HigJan 27, 2025
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An attacker may gain access to protected parts of the file system.

  • CVE-2024-37575HigDec 4, 2024
    risk 0.49cvss 7.5epss 0.00

    The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity…

  • CVE-2024-10458HigOct 29, 2024
    risk 0.49cvss 7.5epss 0.01

    A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

  • CVE-2024-44149HigSep 17, 2024
    risk 0.49cvss 7.5epss 0.01

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.

  • CVE-2024-40770HigSep 17, 2024
    risk 0.49cvss 7.5epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted network settings.

  • CVE-2024-27795HigSep 17, 2024
    risk 0.49cvss 7.5epss 0.01

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the internet.

  • CVE-2024-33892HigAug 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3

  • CVE-2023-52373HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.

  • CVE-2022-48301HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.

  • CVE-2022-48295HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).

  • CVE-2020-18329HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Rehau devices that use a pCOWeb card BIOS v6.27, BOOT v5.00, web version v2.2, allows attackers to gain full unauthenticated access to the configuration and service interface.

  • CVE-2022-36062HigSep 22, 2022
    risk 0.49cvss 7.6epss 0.01

    Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The…

  • CVE-2021-3523HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

  • CVE-2021-37044HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-37006HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.

  • CVE-2021-30482HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly