VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 259 of 327
  • CVE-2022-36865MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.

  • CVE-2022-36864MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.

  • CVE-2022-36856MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.

  • CVE-2022-36832MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.

  • CVE-2022-30745MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.

  • CVE-2022-30715MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

  • CVE-2022-25824MedMar 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

  • CVE-2022-24923MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

  • CVE-2022-23997MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission.

  • CVE-2022-23996MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.

  • CVE-2022-23995MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

  • CVE-2021-4016MedJan 21, 2022
    risk 0.26cvss 4.0epss 0.00

    Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to…

  • CVE-2021-25463MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.

  • CVE-2020-15279MedMay 18, 2021
    risk 0.26cvss 4.0epss 0.00

    An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.

  • CVE-2021-25359MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.

  • CVE-2018-15398MedOct 5, 2018
    risk 0.26cvss 4.0epss 0.02

    A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an…

  • CVE-2026-58429MedAug 13, 2026
    risk 0.25cvss 4.9epss 0.00

    Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

  • CVE-2026-14222LowJul 30, 2026
    risk 0.25cvss 3.8epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.

  • CVE-2026-14221LowJul 30, 2026
    risk 0.25cvss 3.8epss 0.00

    The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment…

  • CVE-2026-22014LowApr 21, 2026
    risk 0.25cvss 3.8epss 0.00

    Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…