VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 282 of 406
  • CVE-2016-4495MedJun 10, 2016
    risk 0.35cvss 5.3epss 0.01

    KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors.

  • CVE-2016-3703MedJun 8, 2016
    risk 0.35cvss 5.3epss 0.01

    Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an…

  • CVE-2016-1694MedJun 5, 2016
    risk 0.35cvss 5.3epss 0.01

    browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority.

  • CVE-2016-1693MedJun 5, 2016
    risk 0.35cvss 5.3epss 0.01

    browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a man-in-the-middle attack…

  • CVE-2016-1692MedJun 5, 2016
    risk 0.35cvss 5.3epss 0.01

    WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same…

  • CVE-2016-2100MedMay 20, 2016
    risk 0.35cvss 5.4epss 0.01

    Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.

  • CVE-2016-1844MedMay 20, 2016
    risk 0.35cvss 5.3epss 0.02

    The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.

  • CVE-2016-1776MedMar 24, 2016
    risk 0.35cvss 5.3epss 0.02

    Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.

  • CVE-2016-1774MedMar 24, 2016
    risk 0.35cvss 5.3epss 0.02

    The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks…

  • CVE-2015-7577MedFeb 16, 2016
    risk 0.35cvss 5.3epss 0.04

    activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote…

  • CVE-2015-5017MedJan 3, 2016
    risk 0.35cvss 5.4epss 0.01

    IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through…

  • CVE-2026-102845MedSep 30, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure.…

  • CVE-2026-101083MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in PMWeb v7.x/v8.x/v2025.x. Impacted is an unknown function in the library encryptionhelper.dll. Such manipulation leads to information disclosure. The attack may be launched remotely. The vendor was contacted early about this…

  • CVE-2026-101055MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_info results in information disclosure. The attack can be executed remotely. The…

  • CVE-2026-101054MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_supplicant.conf of the component TCP Service. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is…

  • CVE-2026-100907MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and…

  • CVE-2026-100906MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used.

  • CVE-2026-100883MedSep 27, 2026
    risk 0.34cvss 6.3epss 0.00

    A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been…

  • CVE-2026-87840MedSep 20, 2026
    risk 0.34cvss 5.3epss 0.00

    The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to…

  • CVE-2026-93504MedSep 18, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The…