VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 210 of 406
  • CVE-2025-30692MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.7-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2025-27738MedApr 8, 2025
    risk 0.42cvss 6.5epss 0.03

    Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

  • CVE-2025-21197MedApr 8, 2025
    risk 0.42cvss 6.5epss 0.03

    Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

  • CVE-2025-2686MedMar 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The…

  • CVE-2025-26138MedMar 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and…

  • CVE-2025-25225MedMar 15, 2025
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions.

  • CVE-2025-2278MedMar 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.

  • CVE-2025-23243MedMar 11, 2025
    risk 0.42cvss 6.5epss 0.02

    NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data tampering or denial of service.

  • CVE-2024-53542MedFeb 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.

  • CVE-2024-39797MedFeb 12, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-36293MedFeb 12, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-24427MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-24426MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-24424MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-24422MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2024-46430MedFeb 10, 2025
    risk 0.42cvss 6.5epss 0.01

    Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted HTTP POST request to the…

  • CVE-2024-57249MedFeb 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the…

  • CVE-2025-23367MedJan 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a…

  • CVE-2025-21185MedJan 17, 2025
    risk 0.42cvss 6.5epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2025-21301MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.02

    Windows Geolocation Service Information Disclosure Vulnerability