VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 82 of 88
  • CVE-2019-11806LowAug 20, 2019
    risk 0.21cvss 3.3epss 0.00

    OX App Suite 7.10.1 and earlier has Insecure Permissions.

  • CVE-2018-20936LowAug 1, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).

  • CVE-2019-14395LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).

  • CVE-2018-12209LowMar 14, 2019
    risk 0.21cvss 3.3epss 0.00

    Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an…

  • CVE-2019-7729LowFeb 22, 2019
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, a malicious app could potentially succeed in retrieving video clips or still images that have been cached for clip sharing. (The Bosch Smart Home App is not…

  • CVE-2012-0433LowJun 8, 2018
    risk 0.21cvss 3.3epss 0.00

    The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.

  • CVE-2017-1699LowJan 4, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.

  • CVE-2017-1716LowDec 13, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638.

  • CVE-2023-34042MedFeb 5, 2024
    risk 0.20cvss 4.1epss 0.00

    The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732: Incorrect Permission…

  • CVE-2023-4777LowSep 8, 2023
    risk 0.20cvss 3.1epss 0.00

    An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins…

  • CVE-2023-4228LowAug 24, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data…

  • CVE-2023-2876LowJun 13, 2023
    risk 0.20cvss 3.1epss 0.00

    Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0…

  • CVE-2023-29092LowMay 9, 2023
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, and Exynos 1080. Binding of a wrong resource can occur due to improper handling of parameters while binding a network interface.

  • CVE-2022-2227LowJul 1, 2022
    risk 0.20cvss 3.1epss 0.01

    Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

  • CVE-2018-1551LowAug 6, 2018
    risk 0.20cvss 3.1epss 0.01

    IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.

  • CVE-2017-15352LowFeb 15, 2018
    risk 0.20cvss 3.1epss 0.00

    Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5500 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5600 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5800 V3, V300R003C00, V300R003C10,…

  • CVE-2026-32684LowMay 12, 2026
    risk 0.19cvss 2.9epss 0.00

    The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information.

  • CVE-2021-41802LowOct 8, 2021
    risk 0.19cvss 2.9epss 0.01

    HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and…

  • CVE-2020-8029LowFeb 11, 2021
    risk 0.19cvss 2.9epss 0.00

    A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.

  • CVE-2023-32114LowJun 13, 2023
    risk 0.18cvss 2.7epss 0.01

    SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the server unavailable which may lead…