CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,103)
page 218 of 406| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15591 | Med | 0.42 | 6.5 | 0.01 | Dec 18, 2019 | An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled. | ||
| CVE-2019-6144 | Med | 0.42 | 6.5 | 0.01 | Oct 23, 2019 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection. | ||
| CVE-2018-20930 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401). | ||
| CVE-2016-10838 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). | ||
| CVE-2016-10857 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60). | ||
| CVE-2016-10856 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29). | ||
| CVE-2016-10852 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85). | ||
| CVE-2019-12470 | Med | 0.42 | 6.5 | 0.01 | Jul 10, 2019 | Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | ||
| CVE-2019-12469 | Med | 0.42 | 6.5 | 0.01 | Jul 10, 2019 | MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | ||
| CVE-2018-19496 | Med | 0.42 | 6.5 | 0.01 | Jul 10, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to… | ||
| CVE-2019-1890 | Med | 0.42 | 6.5 | 0.01 | Jul 4, 2019 | A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized… | ||
| CVE-2018-14864 | Med | 0.42 | 6.5 | 0.01 | Jul 3, 2019 | Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment. | ||
| CVE-2019-10175 | Med | 0.42 | 6.5 | 0.01 | Jun 28, 2019 | A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the source namespace. This could allow users… | ||
| CVE-2017-10721 | Med | 0.42 | 6.5 | 0.02 | Jun 17, 2019 | Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems… | ||
| CVE-2018-18958 | Med | 0.42 | 6.5 | 0.01 | Jun 17, 2019 | OPNsense 18.7.x before 18.7.7 has Incorrect Access Control. | ||
| CVE-2019-12291 | Hig | 0.42 | 7.5 | 0.01 | Jun 6, 2019 | HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured. | ||
| CVE-2019-5014 | Med | 0.42 | 6.5 | 0.01 | May 8, 2019 | An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability. | ||
| CVE-2019-1695 | Med | 0.42 | 6.5 | 0.01 | May 3, 2019 | A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists… | ||
| CVE-2017-18367 | Hig | 0.42 | 7.5 | 0.02 | Apr 24, 2019 | libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single… | ||
| CVE-2018-15631 | Med | 0.42 | 6.5 | 0.01 | Apr 9, 2019 | Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request. |
- risk 0.42cvss 6.5epss 0.01
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
- risk 0.42cvss 6.5epss 0.01
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.
- risk 0.42cvss 6.5epss 0.01
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
- risk 0.42cvss 6.5epss 0.01
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
- risk 0.42cvss 6.5epss 0.01
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to…
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized…
- risk 0.42cvss 6.5epss 0.01
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.
- risk 0.42cvss 6.5epss 0.01
A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the source namespace. This could allow users…
- risk 0.42cvss 6.5epss 0.02
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems…
- risk 0.42cvss 6.5epss 0.01
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
- risk 0.42cvss 7.5epss 0.01
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.
- risk 0.42cvss 6.5epss 0.01
An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists…
- risk 0.42cvss 7.5epss 0.02
libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single…
- risk 0.42cvss 6.5epss 0.01
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.