VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 271 of 327
  • CVE-2024-20912LowJan 16, 2024
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database…

  • CVE-2023-4304LowAug 11, 2023
    risk 0.18cvss 3.8epss 0.01

    Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

  • CVE-2023-33947LowMay 24, 2023
    risk 0.18cvss 2.7epss 0.01

    The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual…

  • CVE-2023-33946LowMay 24, 2023
    risk 0.18cvss 2.7epss 0.01

    The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via…

  • CVE-2022-44622LowNov 3, 2022
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive

  • CVE-2022-3325LowOct 17, 2022
    risk 0.18cvss 2.7epss 0.00

    Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

  • CVE-2021-46270LowMar 2, 2022
    risk 0.18cvss 2.7epss 0.01

    JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

  • CVE-2018-20938LowAug 1, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).

  • CVE-2016-5551LowApr 24, 2017
    risk 0.18cvss 2.8epss 0.00

    Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4.3. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where…

  • CVE-2015-7494LowFeb 8, 2017
    risk 0.18cvss 2.8epss 0.00

    A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain…

  • CVE-2026-47032LowJul 21, 2026
    risk 0.17cvss 2.6epss 0.00

    Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User. …

  • CVE-2026-5124LowMar 30, 2026
    risk 0.17cvss 3.7epss 0.00

    A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The manipulation leads to improper access controls. Remote exploitation of the attack…

  • CVE-2026-5122LowMar 30, 2026
    risk 0.17cvss 3.7epss 0.00

    A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Handler. Performing a manipulation of the argument domainNameLen results in improper access controls. The…

  • CVE-2026-23522LowJan 19, 2026
    risk 0.17cvss 3.7epss 0.00

    LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filter in the database query is…

  • CVE-2024-20911LowFeb 17, 2024
    risk 0.17cvss 2.6epss 0.00

    Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and…

  • CVE-2023-50333LowJan 2, 2024
    risk 0.17cvss 3.7epss 0.00

    Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

  • CVE-2021-37864LowJan 18, 2022
    risk 0.17cvss 2.6epss 0.01

    Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

  • CVE-2021-23173LowJan 10, 2022
    risk 0.17cvss 2.6epss 0.01

    The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.

  • CVE-2026-45266LowJun 1, 2026
    risk 0.16cvss 3.5epss 0.00

    Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions…

  • CVE-2026-34312LowApr 21, 2026
    risk 0.16cvss 2.4epss 0.00

    Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row Access Method privilege with network access via multiple protocols to compromise…