VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 317 of 327
  • CVE-2020-28991CriNov 24, 2020
    risk 0.00cvss 9.8epss 0.02

    Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.

  • CVE-2020-26224HigNov 16, 2020
    risk 0.00cvss 7.5epss 0.02

    In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function that allows a shopping cart to be recreated from an order already placed. The problem is fixed in 1.7.6.9.

  • CVE-2020-15181CriSep 18, 2020
    risk 0.00cvss 9.3epss 0.01

    The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version…

  • CVE-2020-15102MedJul 21, 2020
    risk 0.00cvss 6.5epss 0.01

    In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.

  • CVE-2020-15079MedJul 2, 2020
    risk 0.00cvss 6.4epss 0.01

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6

  • CVE-2020-2025HigMay 19, 2020
    risk 0.00cvss 8.8epss 0.00

    Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all…

  • CVE-2020-1732MedMay 4, 2020
    risk 0.00cvss 4.2epss 0.01

    A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from…

  • CVE-2020-5293MedApr 20, 2020
    risk 0.00cvss 6.5epss 0.01

    In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in 1.7.6.5.

  • CVE-2020-5288MedApr 20, 2020
    risk 0.00cvss 4.1epss 0.01

    "In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.

  • CVE-2020-5287MedApr 20, 2020
    risk 0.00cvss 4.1epss 0.01

    In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.

  • CVE-2020-5279MedApr 20, 2020
    risk 0.00cvss 4.1epss 0.01

    In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/international/translations/ -…

  • CVE-2020-5242HigFeb 20, 2020
    risk 0.00cvss 7.7epss 0.02

    openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Starting with version 2.5.2 all commands need to be whitelisted…

  • CVE-2019-16109MedSep 8, 2019
    risk 0.00cvss 5.3epss 0.02

    An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such…

  • CVE-2019-12243HigJun 5, 2019
    risk 0.00cvss 7.5epss 0.01

    Istio 1.1.x through 1.1.6 has Incorrect Access Control.

  • CVE-2019-1000011MedFeb 4, 2019
    risk 0.00cvss 6.5epss 0.01

    API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This…

  • CVE-2019-1000002MedFeb 4, 2019
    risk 0.00cvss 6.5epss 0.01

    Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write…

  • CVE-2018-1129MedJul 10, 2018
    risk 0.00cvss 6.5epss 0.02

    A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic,…

  • CVE-2016-0611Jan 21, 2016
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

  • CVE-2015-7055Dec 11, 2015
    risk 0.00cvss epss 0.02

    AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

  • CVE-2015-6848Nov 27, 2015
    risk 0.00cvss epss 0.02

    EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remote authenticated AD users to obtain root privileges via unspecified vectors.