VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 213 of 406
  • CVE-2023-32333MedFeb 2, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.

  • CVE-2024-1114MedJan 31, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /application/index/controller/Screen.php. The manipulation of the argument fileUrl leads to improper access controls. The attack can be…

  • CVE-2024-23675MedJan 22, 2024
    risk 0.42cvss 6.5epss 0.00

    In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.

  • CVE-2024-23331HigJan 19, 2024
    risk 0.42cvss 7.5epss 0.01

    Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. This bypass is similar to CVE-2023-34092…

  • CVE-2023-6733MedJan 4, 2024
    risk 0.42cvss 6.5epss 0.00

    The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract…

  • CVE-2023-21751MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Azure DevOps Server Spoofing Vulnerability

  • CVE-2023-45228MedOct 26, 2023
    risk 0.42cvss 6.5epss 0.00

    The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.

  • CVE-2023-20261MedOct 18, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could…

  • CVE-2023-33301MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.00

    An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.

  • CVE-2023-32572MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.

  • CVE-2023-28372MedOct 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock.

  • CVE-2023-39376MedSep 27, 2023
    risk 0.42cvss 6.5epss 0.00

    SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network

  • CVE-2023-4640MedAug 30, 2023
    risk 0.42cvss 6.5epss 0.00

    The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects…

  • CVE-2023-36890MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft SharePoint Server Information Disclosure Vulnerability

  • CVE-2023-37478HigAug 1, 2023
    risk 0.42cvss 7.5epss 0.01

    pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or…

  • CVE-2023-37267HigJul 13, 2023
    risk 0.42cvss 7.5epss 0.01

    Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.

  • CVE-2023-34107MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch…

  • CVE-2023-34106MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information.…

  • CVE-2020-36721MedJun 7, 2023
    risk 0.42cvss 6.5epss 0.01

    The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welco…

  • CVE-2023-2940MedMay 30, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)