VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 58 of 88
  • CVE-2018-12223MedMar 14, 2019
    risk 0.41cvss 6.3epss 0.00

    Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an…

  • CVE-2026-15779MedJul 15, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for…

  • CVE-2026-33430HigMar 26, 2026
    risk 0.40cvss 7.3epss 0.00

    Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and prior to version 0.3.26, if a developer uses Briefcase to produce an Windows MSI installer for a project, and that project is installed for All Users (i.e.,…

  • CVE-2025-67794MedDec 17, 2025
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive ACLs, allowing local users without administrator rights to trigger actions or destabilize the agent.

  • CVE-2025-1139MedAug 20, 2025
    risk 0.40cvss 6.1epss 0.00

    IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authorization to access due to incorrect permission assignment.

  • CVE-2025-0758MedApr 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732)  Description  Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2,…

  • CVE-2024-2905MedApr 25, 2024
    risk 0.40cvss 6.2epss 0.00

    A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive…

  • CVE-2024-21063MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the…

  • CVE-2024-29187HigMar 24, 2024
    risk 0.40cvss 7.3epss 0.00

    WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the…

  • CVE-2024-23223MedJan 23, 2024
    risk 0.40cvss 6.2epss 0.00

    A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to access sensitive user data.

  • CVE-2022-39186MedJan 12, 2023
    risk 0.40cvss 6.2epss 0.00

    EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions

  • CVE-2022-2332MedSep 16, 2022
    risk 0.40cvss 6.2epss 0.00

    A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.

  • CVE-2022-36103HigSep 13, 2022
    risk 0.40cvss 7.2epss 0.01

    Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due to improper validation of the request while signing a worker node CSR (certificate signing request) Talos control plane node…

  • CVE-2022-25172MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.01

    An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack,…

  • CVE-2021-26589MedOct 19, 2021
    risk 0.40cvss 6.1epss 0.01

    A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the…

  • CVE-2020-16990MedNov 11, 2020
    risk 0.40cvss 6.2epss 0.01

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2014-10402MedSep 16, 2020
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

  • CVE-2020-7051MedFeb 13, 2020
    risk 0.40cvss 6.1epss 0.01

    Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.

  • CVE-2019-19736MedDec 30, 2019
    risk 0.40cvss 6.1epss 0.01

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.

  • CVE-2018-19836MedDec 3, 2018
    risk 0.40cvss 6.1epss 0.01

    In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass…