VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 3 of 404
  • CVE-2015-4594CriJan 10, 2017
    risk 0.67cvss 9.8epss 0.06

    eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

  • CVE-2016-8580CriOct 28, 2016
    risk 0.67cvss 9.8epss 0.07

    PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.

  • CVE-2021-38454CriOct 12, 2021
    risk 0.66cvss 10.0epss 0.16

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2016-1000031CriOct 25, 2016
    risk 0.66cvss 9.8epss 0.34

    Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

  • CVE-2016-1044CriMay 11, 2016
    risk 0.66cvss 10.0epss 0.07

    Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a…

  • CVE-2016-1041CriMay 11, 2016
    risk 0.66cvss 10.0epss 0.06

    Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a…

  • CVE-2016-1038CriMay 11, 2016
    risk 0.66cvss 10.0epss 0.07

    Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a…

  • CVE-2026-83944CriSep 17, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-20192CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a…

  • CVE-2026-87230CriSep 15, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-18886CriAug 27, 2026
    risk 0.65cvss —epss 0.00

    ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in…

  • CVE-2026-76607CriAug 22, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.

  • CVE-2026-20315CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-70921CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise…

  • CVE-2026-70880CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP…

  • CVE-2026-61241CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.01

    Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to…

  • CVE-2026-58630CriJul 24, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-46978CriJun 17, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Solaris.…

  • CVE-2026-35308CriJun 17, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker…

  • CVE-2026-35307CriJun 17, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…