VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 150 of 405
  • CVE-2015-3888HigJan 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.

  • CVE-2010-2232HigOct 23, 2017
    risk 0.49cvss 7.5epss 0.04

    In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.

  • CVE-2012-4380HigOct 19, 2017
    risk 0.49cvss 7.5epss 0.02

    MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.

  • CVE-2016-8752HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.02

    Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.

  • CVE-2015-4165HigAug 9, 2017
    risk 0.49cvss 7.5epss 0.04

    The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on which Elasticsearch is running can write to a location that the other application…

  • CVE-2016-10042HigJun 29, 2017
    risk 0.49cvss 7.5epss 0.01

    Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.

  • CVE-2016-6342HigJun 27, 2017
    risk 0.49cvss 7.5epss 0.01

    elog 3.1.1 allows remote attackers to post data as any username in the logbook.

  • CVE-2016-5414HigJun 27, 2017
    risk 0.49cvss 7.5epss 0.01

    FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

  • CVE-2016-7833HigJun 9, 2017
    risk 0.49cvss 7.5epss 0.02

    Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.

  • CVE-2016-7807HigJun 9, 2017
    risk 0.49cvss 7.5epss 0.02

    I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inserted into the product via unspecified vectors.

  • CVE-2016-3112HigJun 8, 2017
    risk 0.49cvss 7.5epss 0.02

    client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading…

  • CVE-2016-0768HigJun 6, 2017
    risk 0.49cvss 7.5epss 0.01

    PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

  • CVE-2016-10370HigMay 11, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and…

  • CVE-2016-2930HigMay 3, 2017
    risk 0.49cvss 7.5epss 0.02

    IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID: 5512.

  • CVE-2016-6337HigApr 20, 2017
    risk 0.49cvss 7.5epss 0.01

    MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.

  • CVE-2016-6331HigApr 20, 2017
    risk 0.49cvss 7.5epss 0.02

    ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.

  • CVE-2017-6919HigApr 20, 2017
    risk 0.49cvss 7.5epss 0.02

    Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.

  • CVE-2016-6605HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.01

    Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

  • CVE-2016-5058HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.01

    OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.

  • CVE-2016-5054HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.01

    OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.