VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 303 of 406
  • CVE-2023-50181MedJul 9, 2024
    risk 0.32cvss 4.9epss 0.00

    An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.

  • CVE-2023-47321MedDec 13, 2023
    risk 0.32cvss 4.9epss 0.01

    Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

  • CVE-2023-41322MedSep 27, 2023
    risk 0.32cvss 4.9epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's…

  • CVE-2023-34469MedSep 12, 2023
    risk 0.32cvss 4.9epss 0.00

    AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the physical network. A successful exploit of this vulnerability may lead to a loss of confidentiality. 

  • CVE-2022-46755MedFeb 11, 2023
    risk 0.32cvss 4.9epss 0.01

    Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.

  • CVE-2022-46678MedFeb 11, 2023
    risk 0.32cvss 4.9epss 0.01

    Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.

  • CVE-2022-46676MedFeb 11, 2023
    risk 0.32cvss 4.9epss 0.01

    Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized.

  • CVE-2022-31708MedDec 16, 2022
    risk 0.32cvss 4.9epss 0.01

    vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

  • CVE-2021-40130MedNov 19, 2021
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog configuration. An…

  • CVE-2015-7315MedSep 25, 2017
    risk 0.32cvss 5.9epss 0.02

    Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.

  • CVE-2015-8140MedJan 30, 2017
    risk 0.32cvss 4.8epss 0.05

    The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sniffing the network.

  • CVE-2016-0731MedMay 18, 2016
    risk 0.32cvss 4.9epss 0.03

    The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.

  • CVE-2016-0225MedFeb 29, 2016
    risk 0.32cvss 4.9epss 0.01

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.

  • CVE-2026-102263MedSep 29, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has…

  • CVE-2026-87965MedSep 18, 2026
    risk 0.31cvss 4.8epss 0.00

    The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so…

  • CVE-2026-82745MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforced primary-key uniqueness on insert. Unlike a SQL data layer, whose unique primary-key constraint rejects…

  • CVE-2026-82629MedAug 31, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of the file jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/MyJwWebJwid3Controller.java of the…

  • CVE-2026-81026MedAug 29, 2026
    risk 0.31cvss 4.8epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access…

  • CVE-2026-76995MedAug 20, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be…

  • CVE-2026-73901MedAug 18, 2026
    risk 0.31cvss 4.8epss 0.00

    Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. …