VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 253 of 327
  • CVE-2015-3295MedJun 7, 2017
    risk 0.28cvss 5.3epss 0.01

    markdown-it before 4.1.0 does not block data: URLs.

  • CVE-2016-1220MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon before 4.2.2 does not properly restrict access.

  • CVE-2016-9462MedMar 28, 2017
    risk 0.28cvss 4.3epss 0.02

    Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only…

  • CVE-2016-9461MedMar 28, 2017
    risk 0.28cvss 4.3epss 0.02

    Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a…

  • CVE-2016-10223MedFeb 14, 2017
    risk 0.28cvss 5.4epss 0.01

    An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP GET parameter passed to the "core/admin/adjax/dashboard/check-module-integrity.php" URL. An attacker could execute arbitrary HTML…

  • CVE-2016-0308MedFeb 8, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.

  • CVE-2016-0320MedFeb 1, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.

  • CVE-2016-6044MedFeb 1, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

  • CVE-2016-8309MedJan 27, 2017
    risk 0.28cvss 4.3epss 0.01

    Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker…

  • CVE-2016-8643MedJan 20, 2017
    risk 0.28cvss 4.3epss 0.01

    In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

  • CVE-2016-8642MedJan 20, 2017
    risk 0.28cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

  • CVE-2016-5621MedOct 25, 2016
    risk 0.28cvss 4.3epss 0.01

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 and 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors related to INFRA, a different…

  • CVE-2016-5613MedOct 25, 2016
    risk 0.28cvss 4.3epss 0.00

    Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5608.

  • CVE-2016-5945MedSep 26, 2016
    risk 0.28cvss 4.3epss 0.01

    IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.

  • CVE-2016-1474MedAug 8, 2016
    risk 0.28cvss 4.3epss 0.01

    Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID…

  • CVE-2016-0357MedJul 15, 2016
    risk 0.28cvss 4.3epss 0.01

    IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site.

  • CVE-2016-5109MedJul 13, 2016
    risk 0.28cvss 4.3epss 0.00

    Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.

  • CVE-2016-2820MedApr 30, 2016
    risk 0.28cvss 4.3epss 0.01

    The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

  • CVE-2016-1658MedApr 18, 2016
    risk 0.28cvss 4.3epss 0.01

    The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.

  • CVE-2016-0757MedApr 13, 2016
    risk 0.28cvss 4.3epss 0.01

    OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.