CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 65 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44794 | Cri | 0.57 | 9.8 | 0.01 | Oct 25, 2023 | An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. | ||
| CVE-2023-32632 | Hig | 0.57 | 8.8 | 0.01 | Oct 11, 2023 | A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-0506 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access. | ||
| CVE-2023-21673 | Hig | 0.57 | 8.7 | 0.00 | Oct 3, 2023 | Improper Access to the VM resource manager can lead to Memory Corruption. | ||
| CVE-2023-4696 | Cri | 0.57 | 9.8 | 0.01 | Sep 1, 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2023-38132 | Hig | 0.57 | 8.8 | 0.00 | Aug 18, 2023 | LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated attacker to log in to telnet service. | ||
| CVE-2023-32009 | Hig | 0.57 | 8.8 | 0.00 | Jun 14, 2023 | Windows Collaborative Translation Framework Elevation of Privilege Vulnerability | ||
| CVE-2021-4361 | Hig | 0.57 | 8.8 | 0.01 | Jun 7, 2023 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update… | ||
| CVE-2020-36700 | Hig | 0.57 | 8.8 | 0.01 | Jun 7, 2023 | The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change… | ||
| CVE-2022-41784 | Hig | 0.57 | 8.8 | 0.00 | May 10, 2023 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access | ||
| CVE-2023-2429 | Cri | 0.57 | 9.8 | 0.01 | Apr 30, 2023 | Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13. | ||
| CVE-2023-24512 | Hig | 0.57 | 8.8 | 0.01 | Apr 25, 2023 | On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the… | ||
| CVE-2022-47542 | Hig | 0.57 | 8.8 | 0.01 | Mar 30, 2023 | Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges. | ||
| CVE-2023-27088 | Hig | 0.57 | 8.8 | 0.01 | Mar 8, 2023 | feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the… | ||
| CVE-2023-26471 | Cri | 0.57 | 9.9 | 0.01 | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means… | ||
| CVE-2022-38935 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2023 | An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges. | ||
| CVE-2023-21777 | Hig | 0.57 | 8.7 | 0.00 | Feb 14, 2023 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | ||
| CVE-2023-21717 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2023 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | ||
| CVE-2022-46754 | Hig | 0.57 | 8.7 | 0.01 | Feb 11, 2023 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities. | ||
| CVE-2023-21846 | Hig | 0.57 | 8.8 | 0.01 | Jan 18, 2023 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple… |
- risk 0.57cvss 9.8epss 0.01
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
- risk 0.57cvss 8.8epss 0.01
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.
- risk 0.57cvss 8.8epss 0.01
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access.
- risk 0.57cvss 8.7epss 0.00
Improper Access to the VM resource manager can lead to Memory Corruption.
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.57cvss 8.8epss 0.00
LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated attacker to log in to telnet service.
- risk 0.57cvss 8.8epss 0.00
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update…
- risk 0.57cvss 8.8epss 0.01
The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change…
- risk 0.57cvss 8.8epss 0.00
Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
- risk 0.57cvss 8.8epss 0.01
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the…
- risk 0.57cvss 8.8epss 0.01
Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.
- risk 0.57cvss 8.8epss 0.01
feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the…
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges.
- risk 0.57cvss 8.7epss 0.00
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- risk 0.57cvss 8.7epss 0.01
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.
- risk 0.57cvss 8.8epss 0.01
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple…