VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 17 of 40
  • CVE-2024-21605MedApr 12, 2024
    risk 0.42cvss 6.5epss 0.00

    An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid link-local traffic is not blocked on…

  • CVE-2023-41120MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a…

  • CVE-2023-36013MedNov 20, 2023
    risk 0.42cvss 6.5epss 0.01

    PowerShell Information Disclosure Vulnerability

  • CVE-2023-36043MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Open Management Infrastructure Information Disclosure Vulnerability

  • CVE-2023-36429MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

  • CVE-2023-39056MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39049MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39046MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39058MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39043MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39040MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39039MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.01

    An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-33368MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.

  • CVE-2023-35151HigJun 23, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki…

  • CVE-2023-34467HigJun 23, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response…

  • CVE-2023-31103HigMay 22, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's…

  • CVE-2023-31206HigMay 22, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0…

  • CVE-2023-27564HigMay 10, 2023
    risk 0.42cvss 7.5epss 0.01

    The n8n package 0.218.0 for Node.js allows Information Disclosure.

  • CVE-2023-2069MedMay 3, 2023
    risk 0.42cvss 6.4epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD…

  • CVE-2023-0485MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates…