CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 122 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-52367 | Hig | 0.50 | 7.7 | 0.00 | Feb 18, 2024 | Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2024-24771 | Hig | 0.50 | 7.7 | 0.01 | Feb 7, 2024 | Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromised could potentially have the… | ||
| CVE-2023-26347 | Hig | 0.50 | 7.5 | 0.10 | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and… | ||
| CVE-2023-31199 | Hig | 0.50 | 7.7 | 0.00 | May 12, 2023 | Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-30768 | Hig | 0.50 | 7.7 | 0.00 | May 12, 2023 | Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-21985 | Hig | 0.50 | 7.7 | 0.00 | Apr 18, 2023 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise… | ||
| CVE-2023-23752 | Med | 0.50 | 5.3 | 1.00 | KEV | Feb 16, 2023 | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | |
| CVE-2023-21752 | Hig | 0.50 | 7.1 | 0.05 | Jan 10, 2023 | Windows Backup Service Elevation of Privilege Vulnerability | ||
| CVE-2022-4809 | Hig | 0.50 | 8.8 | 0.01 | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4803 | Hig | 0.50 | 8.8 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4689 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-4684 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-3225 | Hig | 0.50 | 8.8 | 0.01 | Sep 16, 2022 | Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20. | ||
| CVE-2022-34255 | Hig | 0.50 | 8.8 | 0.02 | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to… | ||
| CVE-2022-1025 | Hig | 0.50 | 8.8 | 0.01 | Jul 12, 2022 | All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level. | ||
| CVE-2022-27838 | Hig | 0.50 | 7.7 | 0.00 | Apr 11, 2022 | Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege. | ||
| CVE-2022-24730 | Hig | 0.50 | 7.7 | 0.01 | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with… | ||
| CVE-2020-4062 | Hig | 0.50 | 8.7 | 0.01 | Jun 22, 2020 | In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain full read & write access to the Conjur Postgres database, including escalating the… | ||
| CVE-2016-8529 | Hig | 0.50 | 7.6 | 0.04 | Feb 15, 2018 | A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version. | ||
| CVE-2017-15914 | Hig | 0.50 | 8.8 | 0.02 | Feb 8, 2018 | Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3. |
- risk 0.50cvss 7.7epss 0.00
Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.50cvss 7.7epss 0.01
Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromised could potentially have the…
- risk 0.50cvss 7.5epss 0.10
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and…
- risk 0.50cvss 7.7epss 0.00
Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.50cvss 7.7epss 0.00
Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.50cvss 7.7epss 0.00
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise…
- risk 0.50cvss 5.3epss 1.00
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- risk 0.50cvss 7.1epss 0.05
Windows Backup Service Elevation of Privilege Vulnerability
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.50cvss 8.8epss 0.01
Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
- risk 0.50cvss 8.8epss 0.02
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to…
- risk 0.50cvss 8.8epss 0.01
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
- risk 0.50cvss 7.7epss 0.00
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.
- risk 0.50cvss 7.7epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with…
- risk 0.50cvss 8.7epss 0.01
In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain full read & write access to the Conjur Postgres database, including escalating the…
- risk 0.50cvss 7.6epss 0.04
A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version.
- risk 0.50cvss 8.8epss 0.02
Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.