VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 69 of 88
  • CVE-2025-38742MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2024-12255MedDec 12, 2024
    risk 0.34cvss 5.3epss 0.01

    The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract…

  • CVE-2024-11176MedNov 20, 2024
    risk 0.34cvss epss 0.00

    Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.

  • CVE-2024-1724MedJul 25, 2024
    risk 0.34cvss 6.3epss 0.00

    In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a…

  • CVE-2024-6739MedJul 15, 2024
    risk 0.34cvss 5.3epss 0.00

    The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

  • CVE-2024-28163MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the…

  • CVE-2024-25645MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.

  • CVE-2024-25644MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.

  • CVE-2024-24740MedFeb 13, 2024
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64UC 7.53, under certain conditions, allows an attacker to access information which could otherwise be restricted with low impact on…

  • CVE-2023-45364MedOct 9, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page…

  • CVE-2023-4565MedSep 27, 2023
    risk 0.34cvss 5.3epss 0.00

    Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable.

  • CVE-2023-41295MedSep 25, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim.

  • CVE-2022-33163MedJun 15, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 228571.

  • CVE-2023-27084MedMar 16, 2023
    risk 0.34cvss 5.3epss 0.00

    Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController parameter.

  • CVE-2022-21946MedMar 16, 2022
    risk 0.34cvss 5.3epss 0.00

    A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue…

  • CVE-2021-41091MedOct 4, 2021
    risk 0.34cvss 6.3epss 0.03

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise…

  • CVE-2021-40066MedSep 16, 2021
    risk 0.34cvss 5.3epss 0.01

    The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in…

  • CVE-2011-2515MedNov 27, 2019
    risk 0.34cvss 5.3epss 0.00

    PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.

  • CVE-2019-2389MedAug 30, 2019
    risk 0.34cvss 5.3epss 0.00

    Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions…

  • CVE-2017-0423MedFeb 8, 2017
    risk 0.34cvss 5.3epss 0.00

    An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android.…