CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,103)
page 275 of 406| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21667 | Med | 0.35 | 6.5 | 0.01 | Jan 11, 2024 | pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure.… | ||
| CVE-2024-21666 | Med | 0.35 | 6.5 | 0.01 | Jan 11, 2024 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions… | ||
| CVE-2024-0358 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2024 | A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been… | ||
| CVE-2023-7223 | Med | 0.35 | 5.3 | 0.01 | Jan 9, 2024 | A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to… | ||
| CVE-2023-50344 | Med | 0.35 | 5.4 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files. | ||
| CVE-2023-50783 | Med | 0.35 | 6.5 | 0.01 | Dec 21, 2023 | Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.… | ||
| CVE-2023-48441 | Med | 0.35 | 5.3 | 0.01 | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user… | ||
| CVE-2023-6758 | Med | 0.35 | 5.3 | 0.01 | Dec 13, 2023 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched… | ||
| CVE-2023-47325 | Med | 0.35 | 5.4 | 0.00 | Dec 13, 2023 | Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces. | ||
| CVE-2023-39228 | Med | 0.35 | 5.3 | 0.01 | Nov 14, 2023 | Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | ||
| CVE-2023-39221 | Med | 0.35 | 5.4 | 0.00 | Nov 14, 2023 | Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. | ||
| CVE-2023-38206 | Med | 0.35 | 5.3 | 0.01 | Sep 14, 2023 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM… | ||
| CVE-2023-40579 | Med | 0.35 | 6.5 | 0.01 | Aug 25, 2023 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with… | ||
| CVE-2023-20230 | Med | 0.35 | 5.4 | 0.00 | Aug 23, 2023 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated… | ||
| CVE-2023-39743 | Med | 0.35 | 5.3 | 0.01 | Aug 17, 2023 | lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c. | ||
| CVE-2021-4352 | Med | 0.35 | 5.3 | 0.01 | Jun 7, 2023 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the… | ||
| CVE-2021-4338 | Med | 0.35 | 6.4 | 0.01 | Jun 7, 2023 | The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit… | ||
| CVE-2023-3095 | Med | 0.35 | 6.5 | 0.00 | Jun 4, 2023 | Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | ||
| CVE-2023-2202 | Med | 0.35 | 6.5 | 0.01 | Apr 21, 2023 | Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3. | ||
| CVE-2023-29922 | Med | 0.35 | 5.3 | 0.03 | Apr 19, 2023 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface. |
- risk 0.35cvss 6.5epss 0.01
pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure.…
- risk 0.35cvss 6.5epss 0.01
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions…
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been…
- risk 0.35cvss 5.3epss 0.01
A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to…
- risk 0.35cvss 5.4epss 0.00
HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.
- risk 0.35cvss 6.5epss 0.01
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.…
- risk 0.35cvss 5.3epss 0.01
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user…
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched…
- risk 0.35cvss 5.4epss 0.00
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
- risk 0.35cvss 5.3epss 0.01
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
- risk 0.35cvss 5.4epss 0.00
Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
- risk 0.35cvss 5.3epss 0.01
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM…
- risk 0.35cvss 6.5epss 0.01
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with…
- risk 0.35cvss 5.4epss 0.00
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated…
- risk 0.35cvss 5.3epss 0.01
lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.
- risk 0.35cvss 5.3epss 0.01
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the…
- risk 0.35cvss 6.4epss 0.01
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit…
- risk 0.35cvss 6.5epss 0.00
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- risk 0.35cvss 6.5epss 0.01
Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3.
- risk 0.35cvss 5.3epss 0.03
PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.