VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 172 of 406
  • CVE-2023-1432HigMar 16, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the component POST Request Handler. The manipulation leads to…

  • CVE-2022-43759HigFeb 7, 2023
    risk 0.47cvss 7.2epss 0.01

    A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to…

  • CVE-2022-34457HigJan 18, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside…

  • CVE-2023-21894HigJan 18, 2023
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged…

  • CVE-2022-39421HigOct 18, 2022
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2022-39857HigOct 7, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.

  • CVE-2022-36263HigAug 19, 2022
    risk 0.47cvss 7.3epss 0.00

    StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.

  • CVE-2022-37393HigAug 16, 2022
    risk 0.47cvss 7.8epss 0.02

    Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as…

  • CVE-2022-2702HigAug 8, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be…

  • CVE-2020-10627HigDec 1, 2021
    risk 0.47cvss 7.3epss 0.00

    Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or…

  • CVE-2021-35528HigNov 17, 2021
    risk 0.47cvss 7.2epss 0.00

    Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to…

  • CVE-2019-10200HigMar 19, 2021
    risk 0.47cvss 7.2epss 0.01

    A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials…

  • CVE-2021-24146HigMar 18, 2021
    risk 0.47cvss 7.5epss 0.31

    Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

  • CVE-2020-7545HigDec 1, 2020
    risk 0.47cvss 7.2epss 0.02

    A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an…

  • CVE-2020-25654HigNov 24, 2020
    risk 0.47cvss 7.2epss 0.02

    An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the…

  • CVE-2018-19588HigJul 11, 2019
    risk 0.47cvss 7.2epss 0.02

    Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.

  • CVE-2018-16553HigJun 20, 2019
    risk 0.47cvss 7.2epss 0.03

    In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.

  • CVE-2016-5714HigOct 18, 2017
    risk 0.47cvss 7.2epss 0.02

    Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol…

  • CVE-2015-4649HigAug 29, 2017
    risk 0.47cvss 7.2epss 0.02

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different vulnerability than CVE-2015-3654.

  • CVE-2015-3657HigAug 29, 2017
    risk 0.47cvss 7.2epss 0.01

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Admin" privileges via unspecified vectors.