VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 298 of 406
  • CVE-2023-26460MedMar 14, 2023
    risk 0.34cvss 5.3epss 0.00

    Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity

  • CVE-2023-1007MedFeb 24, 2023
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the function 0x801120E4 in the library filmfd.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. The attack needs to be…

  • CVE-2022-30564MedFeb 9, 2023
    risk 0.34cvss 5.3epss 0.00

    Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time.

  • CVE-2023-23615MedFeb 3, 2023
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. As a workaround, disable…

  • CVE-2022-47543MedJan 5, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.

  • CVE-2022-44565MedDec 23, 2022
    risk 0.34cvss 5.3epss 0.00

    An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.

  • CVE-2022-38546MedDec 21, 2022
    risk 0.34cvss 5.3epss 0.01

    A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode.

  • CVE-2022-3286MedOct 17, 2022
    risk 0.34cvss 5.3epss 0.00

    Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

  • CVE-2022-39835MedSep 27, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat. The fixed version is 1.5.0.

  • CVE-2022-41235MedSep 21, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.

  • CVE-2022-21950MedSep 7, 2022
    risk 0.34cvss 5.3epss 0.00

    A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to…

  • CVE-2017-20066MedJun 20, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public…

  • CVE-2021-41834MedMay 23, 2022
    risk 0.34cvss 5.3epss 0.01

    JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.

  • CVE-2022-0178MedJan 13, 2022
    risk 0.34cvss 6.3epss 0.01

    Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.

  • CVE-2015-8987MedMar 14, 2017
    risk 0.34cvss 5.3epss 0.01

    Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attackers to make a McAfee Agent talk with another, possibly rogue, ePO server via McAfee Agent migration to another ePO server.

  • CVE-2016-2787MedFeb 13, 2017
    risk 0.34cvss 5.3epss 0.01

    The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

  • CVE-2016-6771MedJan 12, 2017
    risk 0.34cvss 5.3epss 0.00

    An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions:…

  • CVE-2026-21848MedSep 18, 2026
    risk 0.33cvss 5.0epss 0.00

    HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.

  • CVE-2026-81566MedSep 14, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the…

  • CVE-2026-78076MedAug 31, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or…