CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (6,523)
page 267 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21665 | Med | 0.21 | 4.3 | 0.00 | Jan 11, 2024 | ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has… | ||
| CVE-2023-28197 | Low | 0.21 | 3.3 | 0.00 | Jan 10, 2024 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data. | ||
| CVE-2023-42542 | Low | 0.21 | 3.3 | 0.00 | Nov 7, 2023 | Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device. | ||
| CVE-2023-5976 | Med | 0.21 | 4.3 | 0.00 | Nov 7, 2023 | Improper Access Control in GitHub repository microweber/microweber prior to 2.0. | ||
| CVE-2022-38973 | Low | 0.21 | 3.3 | 0.00 | Aug 11, 2023 | Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow an authenticated user to potentially enable denial of service or infomation disclosure via local access. | ||
| CVE-2022-41621 | Low | 0.21 | 3.3 | 0.00 | May 10, 2023 | Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2014-125054 | Med | 0.21 | 4.3 | 0.01 | Jan 7, 2023 | A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identified as… | ||
| CVE-2022-4814 | Med | 0.21 | 4.3 | 0.01 | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4810 | Med | 0.21 | 4.3 | 0.00 | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4807 | Med | 0.21 | 4.3 | 0.01 | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-39915 | Low | 0.21 | 3.3 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent. | ||
| CVE-2022-39864 | Low | 0.21 | 3.3 | 0.00 | Oct 7, 2022 | Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent. | ||
| CVE-2022-39850 | Low | 0.21 | 3.3 | 0.00 | Oct 7, 2022 | Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data. | ||
| CVE-2022-39849 | Low | 0.21 | 3.3 | 0.00 | Oct 7, 2022 | Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data. | ||
| CVE-2022-20358 | Low | 0.21 | 3.3 | 0.00 | Aug 10, 2022 | In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-33701 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent. | ||
| CVE-2022-30752 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action. | ||
| CVE-2022-30751 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action. | ||
| CVE-2022-30750 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected. | ||
| CVE-2022-1810 | Med | 0.21 | 4.3 | 0.01 | May 23, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9. |
- risk 0.21cvss 4.3epss 0.00
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has…
- risk 0.21cvss 3.3epss 0.00
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.
- risk 0.21cvss 4.3epss 0.00
Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
- risk 0.21cvss 3.3epss 0.00
Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow an authenticated user to potentially enable denial of service or infomation disclosure via local access.
- risk 0.21cvss 3.3epss 0.00
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.21cvss 4.3epss 0.01
A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identified as…
- risk 0.21cvss 4.3epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.21cvss 4.3epss 0.00
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.21cvss 4.3epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.
- risk 0.21cvss 3.3epss 0.00
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
- risk 0.21cvss 3.3epss 0.00
Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
- risk 0.21cvss 3.3epss 0.00
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
- risk 0.21cvss 4.3epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.