VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 122 of 405
  • CVE-2023-52367HigFeb 18, 2024
    risk 0.50cvss 7.7epss 0.00

    Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.

  • CVE-2024-24771HigFeb 7, 2024
    risk 0.50cvss 7.7epss 0.01

    Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromised could potentially have the…

  • CVE-2023-26347HigNov 17, 2023
    risk 0.50cvss 7.5epss 0.10

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and…

  • CVE-2023-31199HigMay 12, 2023
    risk 0.50cvss 7.7epss 0.00

    Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-30768HigMay 12, 2023
    risk 0.50cvss 7.7epss 0.00

    Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-21985HigApr 18, 2023
    risk 0.50cvss 7.7epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise…

  • CVE-2023-23752MedKEVFeb 16, 2023
    risk 0.50cvss 5.3epss 1.00

    An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

  • CVE-2023-21752HigJan 10, 2023
    risk 0.50cvss 7.1epss 0.05

    Windows Backup Service Elevation of Privilege Vulnerability

  • CVE-2022-4809HigDec 28, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4803HigDec 28, 2022
    risk 0.50cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4689HigDec 23, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2022-4684HigDec 23, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2022-3225HigSep 16, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.

  • CVE-2022-34255HigAug 16, 2022
    risk 0.50cvss 8.8epss 0.02

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to…

  • CVE-2022-1025HigJul 12, 2022
    risk 0.50cvss 8.8epss 0.01

    All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.

  • CVE-2022-27838HigApr 11, 2022
    risk 0.50cvss 7.7epss 0.00

    Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.

  • CVE-2022-24730HigMar 23, 2022
    risk 0.50cvss 7.7epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with…

  • CVE-2020-4062HigJun 22, 2020
    risk 0.50cvss 8.7epss 0.01

    In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain full read & write access to the Conjur Postgres database, including escalating the…

  • CVE-2016-8529HigFeb 15, 2018
    risk 0.50cvss 7.6epss 0.04

    A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version.

  • CVE-2017-15914HigFeb 8, 2018
    risk 0.50cvss 8.8epss 0.02

    Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.