VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 335 of 404
  • CVE-2025-20144MedMar 12, 2025
    risk 0.26cvss 4.0epss 0.00

    A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect handling of packets when a specific configuration of…

  • CVE-2024-11483MedNov 25, 2024
    risk 0.26cvss 5.0epss 0.01

    A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base.oauth2_provider for OAuth2…

  • CVE-2024-46990MedSep 18, 2024
    risk 0.26cvss 5.0epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `127.127.127.127`). This…

  • CVE-2024-20065MedJun 3, 2024
    risk 0.26cvss 4.0epss 0.00

    In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.

  • CVE-2024-0453MedMay 22, 2024
    risk 0.26cvss 5.0epss 0.00

    The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-0452MedMay 22, 2024
    risk 0.26cvss 5.0epss 0.00

    The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-0451MedMay 22, 2024
    risk 0.26cvss 5.0epss 0.00

    The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2024-30173medApr 2, 2024
    risk 0.26cvss —epss 0.00

    The authentication service of the extension does not verify the OpenID Connect authentication state from the user lookup chain. Instead, the authentication service authenticates every valid frontend user from the user lookup chain, where the frontend user field “tx_oidc” is…

  • CVE-2023-32063MedNov 28, 2023
    risk 0.26cvss 5.0epss 0.01

    OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and…

  • CVE-2023-32062MedNov 27, 2023
    risk 0.26cvss 5.0epss 0.01

    OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.

  • CVE-2023-42540MedNov 7, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.

  • CVE-2023-20267MedNov 1, 2023
    risk 0.26cvss 4.0epss 0.00

    A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit…

  • CVE-2023-35167MedJun 23, 2023
    risk 0.26cvss 5.0epss 0.01

    Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attacker who knows the `id` of an entity instance is not…

  • CVE-2023-21495MedMay 4, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.

  • CVE-2023-21463MedMar 16, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific…

  • CVE-2023-21447MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.

  • CVE-2023-21442MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.

  • CVE-2022-39898MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.

  • CVE-2022-39896MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

  • CVE-2022-39895MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.