VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 211 of 406
  • CVE-2024-40749HigJan 7, 2025
    risk 0.42cvss 7.5epss 0.00

    Improper Access Controls allows access to protected views.

  • CVE-2024-50945HigDec 27, 2024
    risk 0.42cvss 7.5epss 0.01

    An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.

  • CVE-2024-48010MedNov 8, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to escalation of privilege on the application.

  • CVE-2024-51988MedNov 6, 2024
    risk 0.42cvss 6.5epss 0.00

    RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target…

  • CVE-2023-29115MedNov 5, 2024
    risk 0.42cvss 6.5epss 0.00

    In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).

  • CVE-2024-47481MedOct 25, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2024-45118MedOct 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have…

  • CVE-2024-45870MedOct 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.

  • CVE-2024-32940MedSep 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-42021MedSep 7, 2024
    risk 0.42cvss 6.5epss 0.00

    An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

  • CVE-2024-45509MedSep 1, 2024
    risk 0.42cvss 6.5epss 0.00

    In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

  • CVE-2024-6221HigAug 18, 2024
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as…

  • CVE-2024-41332MedAug 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.

  • CVE-2024-41252MedAug 7, 2024
    risk 0.42cvss 6.5epss 0.00

    An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve…

  • CVE-2024-41251MedAug 7, 2024
    risk 0.42cvss 6.5epss 0.00

    An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve…

  • CVE-2024-21169MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.…

  • CVE-2024-40547MedJul 12, 2024
    risk 0.42cvss 6.5epss 0.00

    PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.

  • CVE-2024-36676HigJul 9, 2024
    risk 0.42cvss 7.5epss 0.01

    Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.

  • CVE-2022-41324MedJun 20, 2024
    risk 0.42cvss 6.5epss 0.00

    Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.

  • CVE-2024-5840MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)