VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 94 of 405
  • CVE-2025-50060HigJul 15, 2025
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2023-47294HigJun 23, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.

  • CVE-2025-43586HigJun 10, 2025
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and…

  • CVE-2025-33072HigMay 8, 2025
    risk 0.53cvss 8.1epss 0.02

    Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-30735HigApr 15, 2025
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page and Field Configuration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access…

  • CVE-2025-30288HigApr 8, 2025
    risk 0.53cvss 8.2epss 0.00

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and…

  • CVE-2025-31484CriApr 2, 2025
    risk 0.53cvss —epss 0.00

    conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Between 2025-02-10 and 2025-04-01, conda-forge infrastructure used the wrong token for Azure's cf-staging access. This bug meant that any feedstock maintainer…

  • CVE-2025-20229HigMar 26, 2025
    risk 0.53cvss 8.0epss 0.16

    In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution…

  • CVE-2024-8238HigMar 20, 2025
    risk 0.53cvss 8.1epss 0.01

    In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an attacker to leak server-side secrets or potentially gain…

  • CVE-2024-44313HigMar 18, 2025
    risk 0.53cvss 8.1epss 0.01

    TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

  • CVE-2025-2280HigMar 13, 2025
    risk 0.53cvss 8.1epss 0.01

    Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.

  • CVE-2025-25950HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.00

    Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

  • CVE-2024-12368HigFeb 25, 2025
    risk 0.53cvss 8.1epss 0.01

    Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

  • CVE-2024-56883HigFeb 18, 2025
    risk 0.53cvss 8.1epss 0.01

    Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they…

  • CVE-2024-38310HigFeb 12, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-24411HigFeb 11, 2025
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-24365HigJan 27, 2025
    risk 0.53cvss 8.1epss 0.01

    vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an…

  • CVE-2025-0650HigJan 23, 2025
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can…

  • CVE-2024-49068HigDec 12, 2024
    risk 0.53cvss 8.2epss 0.02

    Microsoft SharePoint Elevation of Privilege Vulnerability

  • CVE-2024-48912HigDec 11, 2024
    risk 0.53cvss 8.1epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.