VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 157 of 405
  • CVE-2020-36838HigOct 16, 2024
    risk 0.48cvss 7.4epss 0.00

    The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own…

  • CVE-2024-38202HigAug 8, 2024
    risk 0.48cvss 7.3epss 0.02

    Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security…

  • CVE-2024-36492HigAug 1, 2024
    risk 0.48cvss 7.4epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.

  • CVE-2024-21740HigJun 25, 2024
    risk 0.48cvss 7.4epss 0.00

    Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.

  • CVE-2024-27264HigMay 22, 2024
    risk 0.48cvss 7.4epss 0.00

    IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 284563.

  • CVE-2024-26203HigMar 12, 2024
    risk 0.48cvss 7.3epss 0.01

    Azure Data Studio Elevation of Privilege Vulnerability

  • CVE-2023-51774HigFeb 29, 2024
    risk 0.48cvss 8.4epss 0.00

    The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.

  • CVE-2024-0712HigJan 19, 2024
    risk 0.48cvss 7.3epss 0.04

    A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affected is an unknown function of the file /useratte/inc/userattea.php. The manipulation leads to improper access controls. It is possible to launch the attack…

  • CVE-2024-20952HigJan 16, 2024
    risk 0.48cvss 7.4epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9,…

  • CVE-2024-20918HigJan 16, 2024
    risk 0.48cvss 7.4epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9,…

  • CVE-2023-21901HigJan 16, 2024
    risk 0.48cvss 7.4epss 0.00

    Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable…

  • CVE-2024-0570HigJan 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely.…

  • CVE-2024-21589HigJan 12, 2024
    risk 0.48cvss 7.4epss 0.00

    An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based attacker to access reports without authenticating, potentially containing sensitive configuration information. A feature was…

  • CVE-2023-51661HigDec 22, 2023
    risk 0.48cvss 8.4epss 0.01

    Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can access the filesystem outside of the sandbox. Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host…

  • CVE-2023-6578HigDec 7, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is possible to launch the attack remotely. To access a file…

  • CVE-2023-36561HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Azure DevOps Server Elevation of Privilege Vulnerability

  • CVE-2021-40699HigSep 7, 2023
    risk 0.48cvss 7.4epss 0.01

    ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary…

  • CVE-2023-1862HigJun 20, 2023
    risk 0.48cvss 7.3epss 0.01

    Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IPC Named Pipe. This would have enabled an attacker to trigger WARP connect and disconnect commands,…

  • CVE-2023-3305HigJun 18, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the file /cgi-bin/jumpto.php?class=user&page=config_save&isphp=1 of the component User Creation Handler. The manipulation of the argument…

  • CVE-2022-21953HigFeb 7, 2023
    risk 0.48cvss 7.4epss 0.00

    A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions…