← Back
CWE-269

2,751 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (2,751)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adtran
1Pmaa
Nov 21, 2024
Mar 27, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary commands via the use of the diagnostic-profile...Show more
An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary commands via the use of the diagnostic-profile over RESTCONF.Show less
1Moodle
1Moodle
Nov 21, 2024
Mar 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
2Fedoraproject
Redhat
2Enterprise Linux
Sssd
Nov 21, 2024
Mar 25, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of d...Show more
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.Show less
1Zeit
1Serve
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has not allowed access to.
1Apache
1Hadoop
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.
1Capmon
1Access Manager
Nov 21, 2024
Mar 15, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to unprivileged users via the --system option.
1F5
1Big Ip Application Acceleration Manager
Nov 21, 2024
Mar 13, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper sc...Show more
In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper scripts.Show less
1Cloudfoundry
1Capi Release
Nov 21, 2024
Mar 13, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed...Show more
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.Show less
1Webmin
1Webmin
Nov 21, 2024
Mar 7, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.
1Cisco
1Nx Os
Nov 21, 2024
Mar 6, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vuln...Show more
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Nov 21, 2024
Mar 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escal...Show more
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.Show less
1Qualcomm
30Mdm9150 Firmware
Mdm9615 FirmwareMdm9625 Firmware+27 more
Nov 21, 2024
Feb 25, 2019
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions M...Show more
Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9150, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8996AU, QCS605, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX20, SXR1130.Show less
1Microfocus
1Filr
Nov 21, 2024
Feb 20, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr...Show more
A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.Show less
4Debian
FedoraprojectGoogle+1 more
6Chrome
Debian LinuxEnterprise Linux Desktop+3 more
Nov 21, 2024
Feb 19, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chr...Show more
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.Show less
1Draeger
4Delta Xl Firmware
Infinity Delta FirmwareInfinity Explorer C700 Firmware+1 more
Nov 21, 2024
Jan 28, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the...Show more
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take control of the operating system.Show less
2Broadcom
Ca
2Service Desk Manager
Service Desk Manager
Nov 21, 2024
Jan 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.
1Drupal
1Drupal
Nov 21, 2024
Jan 15, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only...Show more
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments.Show less
4Canonical
NetappRedhat+1 more
5Active Iq Performance Analytics Services
Element SoftwareEnterprise Linux+2 more
Nov 21, 2024
Jan 14, 2019
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attack...Show more
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/or privileged processes. Versions before v237 are vulnerable.Show less
1Mnc
1Inplc Rt
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute arbitrary code on the Windows system via unspecified vectors.
1Battelle
1V2i Hub
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality. By visiting http://V2I_HUB/UI/powerdown.php, a remote attacker could exploit this vulner...Show more
Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality. By visiting http://V2I_HUB/UI/powerdown.php, a remote attacker could exploit this vulnerability to shut down the system.Show less