VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 348 of 404
  • CVE-2022-1810MedMay 23, 2022
    risk 0.21cvss 4.3epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.

  • CVE-2022-23994LowFeb 11, 2022
    risk 0.21cvss 3.3epss 0.00

    An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

  • CVE-2021-4089MedDec 10, 2021
    risk 0.21cvss 4.3epss 0.01

    snipe-it is vulnerable to Improper Access Control

  • CVE-2021-4026MedNov 30, 2021
    risk 0.21cvss 4.3epss 0.01

    bookstack is vulnerable to Improper Access Control

  • CVE-2021-25954MedAug 9, 2021
    risk 0.21cvss 4.3epss 0.01

    In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at…

  • CVE-2021-25439LowJul 8, 2021
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.

  • CVE-2017-18878MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.

  • CVE-2020-11931LowMay 15, 2020
    risk 0.21cvss 3.3epss 0.00

    An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy…

  • CVE-2019-16554MedDec 17, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.

  • CVE-2017-18421LowAug 2, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).

  • CVE-2019-10189MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.

  • CVE-2019-10188MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.

  • CVE-2019-10187MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

  • CVE-2014-2884LowMar 19, 2018
    risk 0.21cvss 3.3epss 0.00

    The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_OPEN_TEST or (2) TC_IOCTL_GET_SYSTEM_DRIVE_CONFIG IOCTL call.

  • CVE-2016-3733MedApr 20, 2017
    risk 0.21cvss 4.3epss 0.01

    The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.

  • CVE-2016-10148MedJan 18, 2017
    risk 0.21cvss 4.3epss 0.02

    The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin…

  • CVE-2016-6770LowJan 12, 2017
    risk 0.21cvss 3.3epss 0.00

    An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android.…

  • CVE-2016-5615LowOct 25, 2016
    risk 0.21cvss 3.3epss 0.00

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Lynx.

  • CVE-2016-5525LowOct 25, 2016
    risk 0.21cvss 3.3epss 0.00

    Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect integrity via vectors related to Cluster check files.

  • CVE-2016-3276LowJul 13, 2016
    risk 0.21cvss 3.1epss 0.07

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."