VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 219 of 406
  • CVE-2018-12546MedMar 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this…

  • CVE-2019-1690MedMar 11, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The vulnerability is due to a lack of proper access control…

  • CVE-2019-1000021HigFeb 4, 2019
    risk 0.42cvss 7.5epss 0.02

    slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains an incorrect Access Control vulnerability in XEP-0223 plugin (Persistent Storage of Private Data via PubSub) options profile, used for the configuration of default access model that can result in all…

  • CVE-2019-1000011MedFeb 4, 2019
    risk 0.42cvss 6.5epss 0.01

    API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This…

  • CVE-2019-1000002MedFeb 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write…

  • CVE-2018-15459MedJan 23, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device. The vulnerability is due to improper controls on certain pages in the web interface. An…

  • CVE-2017-18353HigDec 17, 2018
    risk 0.42cvss 7.5epss 0.01

    Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.

  • CVE-2018-16476HigNov 30, 2018
    risk 0.42cvss 7.5epss 0.03

    A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions…

  • CVE-2017-2664MedJul 26, 2018
    risk 0.42cvss 6.5epss 0.01

    CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate…

  • CVE-2018-1129MedJul 10, 2018
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic,…

  • CVE-2011-4181HigJun 11, 2018
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.

  • CVE-2018-8922MedJun 1, 2018
    risk 0.42cvss 6.5epss 0.01

    Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders via unspecified vectors.

  • CVE-2016-9645MedApr 10, 2018
    risk 0.42cvss 6.5epss 0.01

    The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.

  • CVE-2014-1400MedApr 10, 2018
    risk 0.42cvss 6.5epss 0.01

    The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.

  • CVE-2014-1399MedApr 10, 2018
    risk 0.42cvss 6.5epss 0.01

    The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.

  • CVE-2014-1398MedApr 10, 2018
    risk 0.42cvss 6.5epss 0.01

    The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.

  • CVE-2017-18101MedApr 10, 2018
    risk 0.42cvss 6.5epss 0.01

    Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations…

  • CVE-2014-3519MedFeb 1, 2018
    risk 0.42cvss 6.5epss 0.00

    The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow local container users with CAP_DAC_READ_SEARCH capability to bypass an intended container protection mechanism and access…

  • CVE-2017-1000483MedJan 3, 2018
    risk 0.42cvss 6.5epss 0.01

    Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

  • CVE-2015-8008HigDec 29, 2017
    risk 0.42cvss 7.5epss 0.03

    The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.