VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 262 of 406
  • CVE-2023-24484MedFeb 16, 2023
    risk 0.36cvss 5.5epss 0.00

    A malicious user can cause log files to be written to a directory that they do not have permission to write to.

  • CVE-2023-21445MedFeb 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.

  • CVE-2022-36442MedJan 10, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK.

  • CVE-2022-42865MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.

  • CVE-2022-42862MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.

  • CVE-2022-42859MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.00

    Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.

  • CVE-2022-42853MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected parts of the file system.

  • CVE-2022-42814MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

  • CVE-2022-42811MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to access user-sensitive data.

  • CVE-2022-32946MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.

  • CVE-2022-32918MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy preferences.

  • CVE-2022-32904MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. An app may be able to access user-sensitive data.

  • CVE-2022-38388MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-Force ID: 233968.

  • CVE-2022-32848MedSep 23, 2022
    risk 0.36cvss 5.5epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a user’s screen.

  • CVE-2022-32800MedSep 23, 2022
    risk 0.36cvss 5.5epss 0.03

    This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.

  • CVE-2022-32789MedSep 23, 2022
    risk 0.36cvss 5.5epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to bypass Privacy preferences.

  • CVE-2022-32783MedSep 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth.

  • CVE-2022-32883MedSep 20, 2022
    risk 0.36cvss 5.5epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.

  • CVE-2022-32834MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.01

    An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.

  • CVE-2022-31475MedJul 21, 2022
    risk 0.36cvss 5.5epss 0.01

    Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.