VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 66 of 88
  • CVE-2023-5651MedNov 20, 2023
    risk 0.35cvss 5.4epss 0.00

    The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

  • CVE-2023-48087MedNov 15, 2023
    risk 0.35cvss 5.4epss 0.00

    xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.

  • CVE-2023-36633MedNov 14, 2023
    risk 0.35cvss 5.4epss 0.00

    An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.

  • CVE-2023-32005MedSep 12, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file stats through the…

  • CVE-2023-20230MedAug 23, 2023
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated…

  • CVE-2023-38991MedAug 4, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.

  • CVE-2023-34797MedJun 15, 2023
    risk 0.35cvss 5.4epss 0.00

    Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information.

  • CVE-2023-31445MedMay 11, 2023
    risk 0.35cvss 5.3epss 0.01

    Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.

  • CVE-2022-23726MedSep 30, 2022
    risk 0.35cvss 5.4epss 0.01

    PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

  • CVE-2020-15329MedSep 29, 2022
    risk 0.35cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.

  • CVE-2020-15328MedSep 29, 2022
    risk 0.35cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.

  • CVE-2022-22330MedSep 13, 2022
    risk 0.35cvss 5.3epss 0.01

    IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 219126.

  • CVE-2022-38183MedAug 12, 2022
    risk 0.35cvss 6.5epss 0.01

    In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to…

  • CVE-2022-34112MedJul 22, 2022
    risk 0.35cvss 6.5epss 0.01

    An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.

  • CVE-2021-38879MedJun 24, 2022
    risk 0.35cvss 5.3epss 0.01

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM…

  • CVE-2021-20355MedJun 24, 2022
    risk 0.35cvss 5.3epss 0.01

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM…

  • CVE-2022-29405MedMay 25, 2022
    risk 0.35cvss 6.5epss 0.02

    In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8

  • CVE-2022-0277MedJan 20, 2022
    risk 0.35cvss 6.5epss 0.01

    Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2020-4146MedNov 12, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 174129.

  • CVE-2021-20526MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 198755.