VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 196 of 406
  • CVE-2016-7226MedNov 10, 2016
    risk 0.43cvss 6.1epss 0.04

    Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

  • CVE-2016-7225MedNov 10, 2016
    risk 0.43cvss 6.1epss 0.04

    Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

  • CVE-2016-7224MedNov 10, 2016
    risk 0.43cvss 6.1epss 0.04

    Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka…

  • CVE-2016-5581MedOct 25, 2016
    risk 0.43cvss 6.6epss 0.00

    Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2016-6802HigSep 20, 2016
    risk 0.43cvss 7.5epss 0.10

    Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

  • CVE-2016-6898MedSep 7, 2016
    risk 0.43cvss 6.6epss 0.01

    XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users to read arbitrary files or cause a denial of service (web service outage) via a crafted XML document.

  • CVE-2016-3245MedJul 13, 2016
    risk 0.43cvss 6.5epss 0.15

    Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability."

  • CVE-2016-3226MedJun 16, 2016
    risk 0.43cvss 6.5epss 0.11

    Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."

  • CVE-2015-7560MedMar 13, 2016
    risk 0.43cvss 6.5epss 0.13

    The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to…

  • CVE-2016-1905HigFeb 3, 2016
    risk 0.43cvss 7.7epss 0.02

    The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.

  • CVE-2026-92099MedSep 19, 2026
    risk 0.42cvss 6.5epss 0.00

    The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases…

  • CVE-2026-11549MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.

  • CVE-2026-82985MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own…

  • CVE-2026-77169MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited…

  • CVE-2026-83460MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of…

  • CVE-2026-83433MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2026-83200MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-83140MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-83097MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP…

  • CVE-2026-83077MedSep 15, 2026
    risk 0.42cvss 6.4epss 0.00

    Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…