CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 78 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33162 | Hig | 0.55 | 8.4 | 0.00 | Feb 23, 2024 | Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-43517 | Hig | 0.55 | 8.4 | 0.00 | Feb 6, 2024 | Memory corruption in Automotive Multimedia due to improper access control in HAB. | ||
| CVE-2023-33071 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities. | ||
| CVE-2023-31100 | Hig | 0.55 | 8.4 | 0.00 | Nov 15, 2023 | Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 before 4.3.1.163 * from 4.4.0.0 before… | ||
| CVE-2023-29157 | Hig | 0.55 | 8.4 | 0.00 | Nov 14, 2023 | Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-41679 | Hig | 0.55 | 8.5 | 0.01 | Oct 10, 2023 | An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission… | ||
| CVE-2023-24844 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range. | ||
| CVE-2023-22014 | Hig | 0.55 | 8.4 | 0.00 | Jul 18, 2023 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft… | ||
| CVE-2023-21491 | Hig | 0.55 | 8.5 | 0.00 | May 4, 2023 | Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege. | ||
| CVE-2023-21642 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2023 | Memory corruption in HAB Memory management due to broad system privileges via physical address. | ||
| CVE-2022-40539 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in Automotive Android OS due to improper validation of array index. | ||
| CVE-2022-33243 | Hig | 0.55 | 8.4 | 0.00 | Feb 12, 2023 | Memory corruption due to improper access control in Qualcomm IPC. | ||
| CVE-2022-27836 | Hig | 0.55 | 8.4 | 0.00 | Apr 11, 2022 | Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary… | ||
| CVE-2021-35245 | Hig | 0.55 | 8.4 | 0.01 | Dec 6, 2021 | When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. | ||
| CVE-2016-4383 | Hig | 0.55 | 8.4 | 0.03 | Jun 27, 2017 | The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change. | ||
| CVE-2016-9976 | Hig | 0.55 | 8.4 | 0.02 | May 3, 2017 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252. | ||
| CVE-2017-3523 | Hig | 0.55 | 8.5 | 0.03 | Apr 24, 2017 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise… | ||
| CVE-2015-4624 | — | Hig | 0.55 | 7.5 | 0.37 | Mar 31, 2017 | Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens. | |
| CVE-2016-0392 | Hig | 0.55 | 8.4 | 0.01 | Jun 19, 2016 | IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a… | ||
| CVE-2015-6862 | Hig | 0.55 | 8.4 | 0.01 | Jan 8, 2016 | HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors. |
- risk 0.55cvss 8.4epss 0.00
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Multimedia due to improper access control in HAB.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
- risk 0.55cvss 8.4epss 0.00
Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 before 4.3.1.163 * from 4.4.0.0 before…
- risk 0.55cvss 8.4epss 0.00
Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.55cvss 8.5epss 0.01
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission…
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
- risk 0.55cvss 8.4epss 0.00
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft…
- risk 0.55cvss 8.5epss 0.00
Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in HAB Memory management due to broad system privileges via physical address.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Android OS due to improper validation of array index.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to improper access control in Qualcomm IPC.
- risk 0.55cvss 8.4epss 0.00
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary…
- risk 0.55cvss 8.4epss 0.01
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
- risk 0.55cvss 8.4epss 0.03
The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
- risk 0.55cvss 8.4epss 0.02
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.
- risk 0.55cvss 8.5epss 0.03
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise…
- risk 0.55cvss 7.5epss 0.37
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
- risk 0.55cvss 8.4epss 0.01
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a…
- risk 0.55cvss 8.4epss 0.01
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.