CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,103)
page 214 of 406| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32060 | Med | 0.42 | 6.5 | 0.01 | May 9, 2023 | DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and 2.39.0, when the Category Option Combination Sharing settings are configured to control access to… | ||
| CVE-2021-44460 | Med | 0.42 | 6.5 | 0.01 | Apr 25, 2023 | Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests. | ||
| CVE-2021-23176 | Med | 0.42 | 6.5 | 0.01 | Apr 25, 2023 | Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets. | ||
| CVE-2023-28312 | Med | 0.42 | 6.5 | 0.01 | Apr 11, 2023 | Azure Machine Learning Information Disclosure Vulnerability | ||
| CVE-2022-24972 | Med | 0.42 | 6.5 | 0.01 | Mar 28, 2023 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | ||
| CVE-2023-26473 | Med | 0.42 | 6.5 | 0.01 | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There is no workaround for this… | ||
| CVE-2022-23240 | Med | 0.42 | 6.5 | 0.00 | Feb 28, 2023 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors. | ||
| CVE-2023-0998 | Med | 0.42 | 6.5 | 0.01 | Feb 24, 2023 | A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access… | ||
| CVE-2023-0994 | Hig | 0.42 | 7.5 | 0.01 | Feb 24, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2. | ||
| CVE-2023-22805 | Med | 0.42 | 6.5 | 0.01 | Feb 15, 2023 | LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from the device. | ||
| CVE-2023-0661 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2023 | Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data. | ||
| CVE-2022-40036 | Med | 0.42 | 6.5 | 0.01 | Jan 26, 2023 | An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component. | ||
| CVE-2022-45166 | Med | 0.42 | 6.5 | 0.00 | Jan 10, 2023 | An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role. | ||
| CVE-2023-0012 | Med | 0.42 | 6.4 | 0.00 | Jan 10, 2023 | In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are… | ||
| CVE-2022-44014 | Med | 0.42 | 6.5 | 0.01 | Dec 25, 2022 | An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQL tables. This leaks all user passwords and MSSQL hashes via /DS/LM_API/api/SelectionService/GetPaggedTab. | ||
| CVE-2022-38655 | Med | 0.42 | 6.4 | 0.00 | Dec 21, 2022 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. | ||
| CVE-2022-45475 | Med | 0.42 | 6.5 | 0.01 | Nov 25, 2022 | Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control. | ||
| CVE-2022-41135 | Med | 0.42 | 6.5 | 0.00 | Nov 18, 2022 | Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress. | ||
| CVE-2022-41652 | Med | 0.42 | 6.5 | 0.01 | Nov 18, 2022 | Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | ||
| CVE-2022-24038 | Med | 0.42 | 6.5 | 0.01 | Nov 18, 2022 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed. |
- risk 0.42cvss 6.5epss 0.01
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and 2.39.0, when the Category Option Combination Sharing settings are configured to control access to…
- risk 0.42cvss 6.5epss 0.01
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
- risk 0.42cvss 6.5epss 0.01
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.
- risk 0.42cvss 6.5epss 0.01
Azure Machine Learning Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
- risk 0.42cvss 6.5epss 0.01
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There is no workaround for this…
- risk 0.42cvss 6.5epss 0.00
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access…
- risk 0.42cvss 7.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.
- risk 0.42cvss 6.5epss 0.01
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from the device.
- risk 0.42cvss 6.5epss 0.01
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role.
- risk 0.42cvss 6.4epss 0.00
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQL tables. This leaks all user passwords and MSSQL hashes via /DS/LM_API/api/SelectionService/GetPaggedTab.
- risk 0.42cvss 6.4epss 0.00
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
- risk 0.42cvss 6.5epss 0.01
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.
- risk 0.42cvss 6.5epss 0.00
Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
- risk 0.42cvss 6.5epss 0.01
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
- risk 0.42cvss 6.5epss 0.01
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.