VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 215 of 406
  • CVE-2022-22442MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.01

    "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427."

  • CVE-2022-33757MedOct 25, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of information on the scan target and/or the Nessus scan to unauthorized parties able to reach the Nessus…

  • CVE-2021-44776MedOct 24, 2022
    risk 0.42cvss 6.5epss 0.00

    A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbitrarily change the security access rights to KVM and Virtual Media functionalities. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

  • CVE-2021-26732MedOct 24, 2022
    risk 0.42cvss 6.5epss 0.00

    A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

  • CVE-2022-3067MedOct 17, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read…

  • CVE-2022-28761MedOct 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting…

  • CVE-2022-28760MedOct 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

  • CVE-2022-34431MedOct 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Dell Hybrid Client below 1.8 version contains a guest user profile corruption vulnerability. A WMS privilege attacker could potentially exploit this vulnerability, leading to DHC system not being accessible.

  • CVE-2022-39854MedOct 7, 2022
    risk 0.42cvss 6.4epss 0.00

    Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

  • CVE-2022-36771MedSep 28, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.

  • CVE-2022-32880MedSep 20, 2022
    risk 0.42cvss 6.5epss 0.01

    This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data.

  • CVE-2022-36024HigAug 18, 2022
    risk 0.42cvss 7.5epss 0.01

    py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the `application.commands` scope without the `bot` scope. Currently, it appears that all public bots that…

  • CVE-2022-33925MedAug 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information.

  • CVE-2022-21586MedJul 19, 2022
    risk 0.42cvss 6.4epss 0.01

    Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2022-20859MedJul 6, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform…

  • CVE-2011-1762MedApr 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

  • CVE-2021-40405MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-25650MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All versions < V8.18.14), Mendix Applications using Mendix 9 (All versions < V9.12.0), Mendix Applications using Mendix 9 (V9.6) (All versions…

  • CVE-2022-26317MedMar 8, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microflow execution call the affected framework does not correctly verify, if the request was initially made by the user requesting the…

  • CVE-2021-41543MedMar 8, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could…