VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 141 of 405
  • CVE-2024-56335HigDec 20, 2024
    risk 0.49cvss 7.6epss 0.00

    vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a user account in the server. 2.…

  • CVE-2024-50653HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

  • CVE-2024-39609HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Access Control in UEFI firmware for some Intel(R) Server Board M70KLP may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-38204HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-21195HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.00

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-45408HigOct 1, 2024
    risk 0.49cvss 7.5epss 0.00

    eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to access several kinds of otherwise restricted information. If anonymous access is allowed (something disabled by default),…

  • CVE-2024-44860HigSep 26, 2024
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.

  • CVE-2024-46610HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.00

    An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

  • CVE-2024-46609HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.01

    An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords

  • CVE-2024-46607HigSep 25, 2024
    risk 0.49cvss 7.6epss 0.01

    Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.

  • CVE-2023-43626HigSep 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-30587HigSep 7, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector). By exploiting the Worker class's ability to create an "internal worker" with the kIsInternal Symbol, attackers…

  • CVE-2023-30583HigSep 7, 2024
    risk 0.49cvss 7.5epss 0.01

    fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the…

  • CVE-2024-43477HigAug 23, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

  • CVE-2024-42772HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.

  • CVE-2024-36443HigAug 22, 2024
    risk 0.49cvss 7.6epss 0.01

    Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

  • CVE-2024-27187HigAug 20, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Access Controls allows backend users to overwrite their username when disallowed.

  • CVE-2024-41518HigAug 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.

  • CVE-2024-40786HigJul 29, 2024
    risk 0.49cvss 7.5epss 0.01

    This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8. An attacker may be able to view sensitive user information.

  • CVE-2024-41600HigJul 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.