VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 214 of 406
  • CVE-2023-32060MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.01

    DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and 2.39.0, when the Category Option Combination Sharing settings are configured to control access to…

  • CVE-2021-44460MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.

  • CVE-2021-23176MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.

  • CVE-2023-28312MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Azure Machine Learning Information Disclosure Vulnerability

  • CVE-2022-24972MedMar 28, 2023
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2023-26473MedMar 2, 2023
    risk 0.42cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There is no workaround for this…

  • CVE-2022-23240MedFeb 28, 2023
    risk 0.42cvss 6.5epss 0.00

    Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.

  • CVE-2023-0998MedFeb 24, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access…

  • CVE-2023-0994HigFeb 24, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

  • CVE-2023-22805MedFeb 15, 2023
    risk 0.42cvss 6.5epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from the device.

  • CVE-2023-0661MedFeb 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

  • CVE-2022-40036MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component.

  • CVE-2022-45166MedJan 10, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data unrelated to their role.

  • CVE-2023-0012MedJan 10, 2023
    risk 0.42cvss 6.4epss 0.00

    In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are…

  • CVE-2022-44014MedDec 25, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQL tables. This leaks all user passwords and MSSQL hashes via /DS/LM_API/api/SelectionService/GetPaggedTab.

  • CVE-2022-38655MedDec 21, 2022
    risk 0.42cvss 6.4epss 0.00

    BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.

  • CVE-2022-45475MedNov 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.

  • CVE-2022-41135MedNov 18, 2022
    risk 0.42cvss 6.5epss 0.00

    Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.

  • CVE-2022-41652MedNov 18, 2022
    risk 0.42cvss 6.5epss 0.01

    Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

  • CVE-2022-24038MedNov 18, 2022
    risk 0.42cvss 6.5epss 0.01

    Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.