VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 267 of 327
  • CVE-2024-21665MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has…

  • CVE-2023-28197LowJan 10, 2024
    risk 0.21cvss 3.3epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.

  • CVE-2023-42542LowNov 7, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.

  • CVE-2023-5976MedNov 7, 2023
    risk 0.21cvss 4.3epss 0.00

    Improper Access Control in GitHub repository microweber/microweber prior to 2.0.

  • CVE-2022-38973LowAug 11, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow an authenticated user to potentially enable denial of service or infomation disclosure via local access.

  • CVE-2022-41621LowMay 10, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2014-125054MedJan 7, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identified as…

  • CVE-2022-4814MedDec 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4810MedDec 28, 2022
    risk 0.21cvss 4.3epss 0.00

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4807MedDec 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-39915LowDec 8, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.

  • CVE-2022-39864LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.

  • CVE-2022-39850LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

  • CVE-2022-39849LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

  • CVE-2022-20358LowAug 10, 2022
    risk 0.21cvss 3.3epss 0.00

    In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2022-33701LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.

  • CVE-2022-30752LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.

  • CVE-2022-30751LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.

  • CVE-2022-30750LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.

  • CVE-2022-1810MedMay 23, 2022
    risk 0.21cvss 4.3epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.