VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 212 of 406
  • CVE-2024-30481MedJun 9, 2024
    risk 0.42cvss 6.5epss 0.00

    Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.0.0.

  • CVE-2023-43849MedMay 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit a firmware image via HTTP POST requests. This may result in DoS or remote code execution.

  • CVE-2024-33647MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.

  • CVE-2024-23271MedApr 24, 2024
    risk 0.42cvss 6.5epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.

  • CVE-2024-22807MedApr 22, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machine to lose network connectivity and suffer from firmware corruption.

  • CVE-2024-21091MedApr 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP…

  • CVE-2024-21424MedApr 9, 2024
    risk 0.42cvss 6.5epss 0.02

    Azure Compute Gallery Elevation of Privilege Vulnerability

  • CVE-2024-31805MedApr 8, 2024
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.

  • CVE-2024-2447MedApr 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.

  • CVE-2024-25811MedMar 21, 2024
    risk 0.42cvss 6.5epss 0.01

    An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.

  • CVE-2024-1144MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthenticated user to access the application's functionalities without the need for credentials.

  • CVE-2024-2481MedMar 15, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The manipulation of the argument del leads to improper access controls. It is possible to launch…

  • CVE-2024-1668MedMar 13, 2024
    risk 0.42cvss 6.5epss 0.01

    The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to…

  • CVE-2024-28120MedMar 11, 2024
    risk 0.42cvss 6.5epss 0.01

    codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when receiving an external message. This allows an attacker to host a website that will steal the user's Codeium…

  • CVE-2024-20929MedFeb 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-0032MedFeb 16, 2024
    risk 0.42cvss 6.5epss 0.00

    In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-1439MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

  • CVE-2024-23446MedFeb 7, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain…

  • CVE-2021-46903MedFeb 4, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in violation of expected access control).

  • CVE-2023-38263MedFeb 2, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577.