VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 29 of 40
  • CVE-2024-27137MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The…

  • CVE-2024-21597MedJan 12, 2024
    risk 0.34cvss 5.3epss 0.00

    An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) scenario if…

  • CVE-2023-44102MedOct 11, 2023
    risk 0.34cvss 5.3epss 0.00

    Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.

  • CVE-2023-40788MedSep 19, 2023
    risk 0.34cvss 5.3epss 0.01

    SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs

  • CVE-2023-4230MedAug 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the…

  • CVE-2023-39974MedAug 17, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.

  • CVE-2023-39155MedJul 26, 2023
    risk 0.34cvss 5.3epss 0.01

    Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.

  • CVE-2023-3456MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-33518MedJun 5, 2023
    risk 0.34cvss 5.3epss 0.00

    emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.

  • CVE-2023-33293MedMay 22, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is…

  • CVE-2023-25192MedFeb 15, 2023
    risk 0.34cvss 5.3epss 0.01

    AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.

  • CVE-2018-25068MedJan 6, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.…

  • CVE-2019-9011MedDec 26, 2022
    risk 0.34cvss 5.3epss 0.00

    In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.

  • CVE-2022-1911MedNov 30, 2022
    risk 0.34cvss 5.3epss 0.01

    Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.

  • CVE-2022-24747MedMar 9, 2022
    risk 0.34cvss 6.3epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and client then headers may be…

  • CVE-2021-37112MedJan 3, 2022
    risk 0.34cvss 5.3epss 0.00

    Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability may lead to Firmware leak.

  • CVE-2021-21334MedMar 10, 2021
    risk 0.34cvss 6.3epss 0.02

    In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may…

  • CVE-2023-2025MedMay 18, 2023
    risk 0.33cvss 5.0epss 0.01

    OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.

  • CVE-2022-24742MedMar 14, 2022
    risk 0.33cvss 5.0epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must…

  • CVE-2021-36002MedSep 1, 2021
    risk 0.33cvss 5.0epss 0.01

    Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. The attacker must plant a malicious file in a particular…