VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 218 of 406
  • CVE-2019-15591MedDec 18, 2019
    risk 0.42cvss 6.5epss 0.01

    An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

  • CVE-2019-6144MedOct 23, 2019
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.

  • CVE-2018-20930MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).

  • CVE-2016-10838MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).

  • CVE-2016-10857MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

  • CVE-2016-10856MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

  • CVE-2016-10852MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

  • CVE-2019-12470MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2019-12469MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2018-19496MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to…

  • CVE-2019-1890MedJul 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized…

  • CVE-2018-14864MedJul 3, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.

  • CVE-2019-10175MedJun 28, 2019
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the source namespace. This could allow users…

  • CVE-2017-10721MedJun 17, 2019
    risk 0.42cvss 6.5epss 0.02

    Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems…

  • CVE-2018-18958MedJun 17, 2019
    risk 0.42cvss 6.5epss 0.01

    OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.

  • CVE-2019-12291HigJun 6, 2019
    risk 0.42cvss 7.5epss 0.01

    HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.

  • CVE-2019-5014MedMay 8, 2019
    risk 0.42cvss 6.5epss 0.01

    An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.

  • CVE-2019-1695MedMay 3, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists…

  • CVE-2017-18367HigApr 24, 2019
    risk 0.42cvss 7.5epss 0.02

    libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single…

  • CVE-2018-15631MedApr 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.