CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 143 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-29841 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user | ||
| CVE-2024-29840 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user | ||
| CVE-2024-29839 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user | ||
| CVE-2024-1308 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated… | ||
| CVE-2024-27895 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-52537 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-30418 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2024 | Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-36644 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2024 | Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin. | ||
| CVE-2023-36643 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2024 | Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function. | ||
| CVE-2024-27605 | Hig | 0.49 | 7.5 | 0.00 | Apr 2, 2024 | Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system. | ||
| CVE-2022-47037 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2024 | Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials. | ||
| CVE-2023-49545 | Hig | 0.49 | 7.5 | 0.01 | Mar 1, 2024 | A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | ||
| CVE-2023-52375 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2024 | Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-44031 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2024 | Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted POST request. | ||
| CVE-2023-47034 | Hig | 0.49 | 7.5 | 0.00 | Jan 19, 2024 | A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors. | ||
| CVE-2024-20932 | Hig | 0.49 | 7.5 | 0.01 | Jan 16, 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition:… | ||
| CVE-2023-52105 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-52099 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52114 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2023-51070 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2024 | An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server. |
- risk 0.49cvss 7.5epss 0.01
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user
- risk 0.49cvss 7.5epss 0.01
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user
- risk 0.49cvss 7.5epss 0.01
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
- risk 0.49cvss 7.5epss 0.01
The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated…
- risk 0.49cvss 7.5epss 0.00
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.01
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.
- risk 0.49cvss 7.5epss 0.01
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.
- risk 0.49cvss 7.5epss 0.00
Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.
- risk 0.49cvss 7.5epss 0.01
Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.
- risk 0.49cvss 7.5epss 0.01
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted POST request.
- risk 0.49cvss 7.5epss 0.00
A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition:…
- risk 0.49cvss 7.5epss 0.00
The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.
- risk 0.49cvss 7.5epss 0.01
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.