VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 217 of 406
  • CVE-2021-26118HigJan 27, 2021
    risk 0.42cvss 7.5epss 0.04

    While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in…

  • CVE-2019-11784MedDec 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.

  • CVE-2019-11783MedDec 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

  • CVE-2019-11782MedDec 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.

  • CVE-2018-15645MedDec 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.

  • CVE-2020-35497MedDec 21, 2020
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.

  • CVE-2020-7573MedNov 19, 2020
    risk 0.42cvss 6.5epss 0.01

    A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control.

  • CVE-2020-25698HigNov 19, 2020
    risk 0.42cvss 7.5epss 0.02

    Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2…

  • CVE-2020-3482MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is due to improper…

  • CVE-2020-3592MedNov 6, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system. The vulnerability is due to insufficient authorization checking on an…

  • CVE-2020-10930MedJul 28, 2020
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of URLs. The…

  • CVE-2020-15102MedJul 21, 2020
    risk 0.42cvss 6.5epss 0.01

    In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.

  • CVE-2020-8196MedKEVJul 10, 2020
    risk 0.42cvss 4.3epss 0.26

    Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

  • CVE-2020-15079MedJul 2, 2020
    risk 0.42cvss 6.4epss 0.01

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6

  • CVE-2020-5293MedApr 20, 2020
    risk 0.42cvss 6.5epss 0.01

    In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in 1.7.6.5.

  • CVE-2020-8139MedMar 20, 2020
    risk 0.42cvss 6.5epss 0.02

    A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

  • CVE-2019-5474MedJan 28, 2020
    risk 0.42cvss 6.5epss 0.01

    An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

  • CVE-2019-15255MedJan 26, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to…

  • CVE-2019-18275MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.01

    OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauthorized tag data when viewing analysis data reference attributes.

  • CVE-2020-1604MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.01

    On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certain packets to fail. This issue only affects firewall filter evaluation of certain packets destined to the device Routing Engine…