VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (1,923)

page 29 of 97
  • CVE-2016-6337HigApr 20, 2017
    risk 0.49cvss 7.5epss 0.00

    MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.

  • CVE-2016-6331HigApr 20, 2017
    risk 0.49cvss 7.5epss 0.00

    ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.

  • CVE-2016-6605HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

  • CVE-2016-5058HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.

  • CVE-2016-5054HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.

  • CVE-2015-7265HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.

  • CVE-2015-7263HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.

  • CVE-2014-3930HigApr 3, 2017
    risk 0.49cvss 7.5epss 0.00

    lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain IP addresses and other unspecified router credentials.

  • CVE-2014-3929HigApr 3, 2017
    risk 0.49cvss 7.5epss 0.01

    The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote attackers to obtain private ssh keys.

  • CVE-2016-8798HigApr 2, 2017
    risk 0.49cvss 7.5epss 0.00

    Huawei USG5500 with software V300R001C00 and V300R001C00 allows attackers to bypass the anti-DDoS module of the USGs to cause a denial of service condition on the backend server.

  • CVE-2016-5747HigMar 23, 2017
    risk 0.49cvss 7.5epss 0.00

    A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.

  • CVE-2016-9368HigMar 14, 2017
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.

  • CVE-2016-8236HigMar 3, 2017
    risk 0.49cvss 7.5epss 0.00

    Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77.

  • CVE-2016-9956HigFeb 22, 2017
    risk 0.49cvss 7.5epss 0.02

    The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

  • CVE-2016-5801HigFeb 13, 2017
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web application may allow an attacker to gain access by brute forcing account passwords.

  • CVE-2016-10026HigFeb 13, 2017
    risk 0.49cvss 7.5epss 0.00

    ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.

  • CVE-2016-9008HigFeb 1, 2017
    risk 0.49cvss 7.5epss 0.00

    IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.

  • CVE-2016-2942HigFeb 1, 2017
    risk 0.49cvss 7.5epss 0.00

    IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine.

  • CVE-2016-9415HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.01

    MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."

  • CVE-2016-7952HigDec 13, 2016
    risk 0.49cvss 7.5epss 0.01

    X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.