VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,083)

page 354 of 405
  • CVE-2024-11138LowNov 12, 2024
    risk 0.18cvss 2.7epss 0.03

    A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The…

  • CVE-2024-45149LowOct 10, 2024
    risk 0.18cvss 2.7epss 0.00

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have…

  • CVE-2024-45135LowOct 10, 2024
    risk 0.18cvss 2.7epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security measures and have a low…

  • CVE-2024-45133LowOct 10, 2024
    risk 0.18cvss 2.7epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may…

  • CVE-2024-39837LowAug 1, 2024
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

  • CVE-2024-29977LowAug 1, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts

  • CVE-2024-2880LowJul 11, 2024
    risk 0.18cvss 2.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission could ban group members.

  • CVE-2024-36257LowJul 3, 2024
    risk 0.18cvss 2.7epss 0.00

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one…

  • CVE-2024-20912LowJan 16, 2024
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database…

  • CVE-2023-4304LowAug 11, 2023
    risk 0.18cvss 3.8epss 0.01

    Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

  • CVE-2023-33947LowMay 24, 2023
    risk 0.18cvss 2.7epss 0.01

    The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual…

  • CVE-2023-33946LowMay 24, 2023
    risk 0.18cvss 2.7epss 0.01

    The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via…

  • CVE-2022-44622LowNov 3, 2022
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive

  • CVE-2022-3325LowOct 17, 2022
    risk 0.18cvss 2.7epss 0.00

    Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

  • CVE-2021-46270LowMar 2, 2022
    risk 0.18cvss 2.7epss 0.01

    JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

  • CVE-2018-20938LowAug 1, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).

  • CVE-2016-5551LowApr 24, 2017
    risk 0.18cvss 2.8epss 0.00

    Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4.3. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where…

  • CVE-2015-7494LowFeb 8, 2017
    risk 0.18cvss 2.8epss 0.00

    A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain…

  • CVE-2026-61700LowSep 17, 2026
    risk 0.17cvss 3.7epss 0.00

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When…

  • CVE-2026-70776LowAug 18, 2026
    risk 0.17cvss 2.6epss 0.00

    Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…