VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 263 of 327
  • CVE-2024-30107LowApr 18, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

  • CVE-2023-40170MedAug 28, 2023
    risk 0.23cvss 4.6epss 0.01

    jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in…

  • CVE-2023-4546LowAug 26, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The manipulation leads to improper access controls. The exploit…

  • CVE-2023-33191MedMay 30, 2023
    risk 0.23cvss 4.6epss 0.00

    Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurity `validate.podSecurity` subrule in Kyverno 1.9.2 and 1.9.3 are vulnerable. This issue was patched in version 1.9.4.

  • CVE-2023-2112LowApr 20, 2023
    risk 0.23cvss 3.6epss 0.00

    Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.

  • CVE-2015-10057MedJan 16, 2023
    risk 0.23cvss 4.6epss 0.01

    A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file inc/class.securelogin.php of the component Password Reset Handler. The manipulation leads to improper access…

  • CVE-2022-34894LowJul 1, 2022
    risk 0.23cvss 3.5epss 0.01

    In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services

  • CVE-2020-8902LowFeb 23, 2021
    risk 0.23cvss 3.5epss 0.00

    Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot.…

  • CVE-2016-4874LowApr 17, 2017
    risk 0.23cvss 3.5epss 0.01

    Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.

  • CVE-2026-60847LowJul 21, 2026
    risk 0.22cvss 3.4epss 0.00

    Vulnerability in the Oracle Order Entry product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle…

  • CVE-2023-0657LowNov 17, 2024
    risk 0.22cvss 3.4epss 0.00

    A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.

  • CVE-2024-3164MedApr 1, 2024
    risk 0.22cvss 4.5epss 0.00

    In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access…

  • CVE-2022-23132LowJan 13, 2022
    risk 0.22cvss 3.3epss 0.01

    During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level

  • CVE-2016-10549MedMay 31, 2018
    risk 0.22cvss 4.4epss 0.01

    Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the value for the Access-Control-Allow-Origin header. This would allow an attacker to…

  • CVE-2026-58039LowJul 31, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects…

  • CVE-2026-61071LowJul 21, 2026
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2026-47055LowJul 21, 2026
    risk 0.21cvss 3.2epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes…

  • CVE-2026-21953LowJul 21, 2026
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2026-48936LowJun 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

  • CVE-2026-11459LowJun 7, 2026
    risk 0.21cvss 3.3epss 0.00

    A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The…