VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 35 of 405
  • CVE-2026-61207CriJul 21, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-46913CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure…

  • CVE-2026-46912CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-46805CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-46795CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-35306CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-35305CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-45043CriMay 29, 2026
    risk 0.60cvss —epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user…

  • CVE-2025-27724CriJul 28, 2025
    risk 0.60cvss 9.3epss 0.01

    A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilities. An attacker can upload a malicious file to trigger this vulnerability.

  • CVE-2025-43563CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.15

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-30281CriApr 8, 2025
    risk 0.60cvss 9.1epss 0.24

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-25948CriMar 3, 2025
    risk 0.60cvss 9.1epss 0.07

    Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

  • CVE-2024-56898HigFeb 3, 2025
    risk 0.60cvss 8.8epss 0.03

    Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

  • CVE-2024-56330CriDec 20, 2024
    risk 0.60cvss —epss 0.00

    Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC) is not disabled. This would allow users within a container to access another containers agent, therefore compromising access.The problem has been patched in…

  • CVE-2024-29990CriApr 9, 2024
    risk 0.60cvss 9.0epss 0.18

    Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

  • CVE-2024-21364CriFeb 13, 2024
    risk 0.60cvss 9.3epss 0.01

    Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2023-0744CriFeb 8, 2023
    risk 0.60cvss 9.8epss 0.06

    Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2020-8973CriOct 17, 2022
    risk 0.60cvss 9.3epss 0.00

    ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected asset is located, to operate and change several parameters without having to be…

  • CVE-2022-0143CriSep 19, 2022
    risk 0.60cvss 9.3epss 0.01

    When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)

  • CVE-2020-2506HigKEVFeb 3, 2021
    risk 0.60cvss 7.3epss 0.02

    The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP…