VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 240 of 406
  • CVE-2023-3018MedMay 31, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/?page=user/list. The manipulation leads to improper access controls. The attack can be initiated…

  • CVE-2023-2670MedMay 12, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/?page=user/manage_user. The manipulation leads to improper access controls. The attack can be initiated…

  • CVE-2023-1557MedMar 22, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ecommerce/admin/user/controller.php?action=edit of the component Username Handler. The manipulation of the argument…

  • CVE-2023-21860MedJan 18, 2023
    risk 0.41cvss 6.3epss 0.01

    Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected are 7.4.38 and prior, 7.5.28 and prior, 7.6.24 and prior and 8.0.31 and prior. Difficult to exploit vulnerability allows high privileged…

  • CVE-2021-4300MedJan 4, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIndex of the file src/main.cpp of the component Block Verification. The manipulation leads to improper access controls. The attack…

  • CVE-2022-23513MedDec 23, 2022
    risk 0.41cvss 5.3epss 0.41

    Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of…

  • CVE-2022-3771MedOct 31, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php of the component File Upload Management. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The…

  • CVE-2022-33931MedAug 10, 2022
    risk 0.41cvss 6.3epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no access to Alert Classification page could potentially exploit this vulnerability, leading to the change the alert categories.

  • CVE-2022-2578MedJul 29, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action/createUser.php. The manipulation leads to improper access controls. The attack may be initiated…

  • CVE-2022-1958MedJun 15, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. Upgrading to version 21.3.5.18513 is able to…

  • CVE-2021-35221MedAug 31, 2021
    risk 0.41cvss 6.3epss 0.02

    Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

  • CVE-2020-14388MedJun 2, 2021
    risk 0.41cvss 6.3epss 0.01

    A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions and access API services where they do not have permission.

  • CVE-2020-3522MedAug 26, 2020
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the device. The…

  • CVE-2020-16241MedAug 21, 2020
    risk 0.41cvss 6.3epss 0.00

    Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2017-18403MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).

  • CVE-2018-15611MedSep 27, 2018
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.

  • CVE-2016-8007MedMar 14, 2017
    risk 0.41cvss 6.3epss 0.00

    Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipulate the product's registry keys via specific conditions.

  • CVE-2016-5990MedFeb 1, 2017
    risk 0.41cvss 6.3epss 0.01

    IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.

  • CVE-2016-8299MedJan 27, 2017
    risk 0.41cvss 6.3epss 0.01

    Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows low…

  • CVE-2016-5604MedOct 25, 2016
    risk 0.41cvss 6.3epss 0.00

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-3563.