← Back
CWE-284

5,081 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,081)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Nextcloud
2Fedora
Group Folders
Nov 21, 2024
May 12, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
1Cisco
3Integrated Management Controller Supervisor
Ucs DirectorUcs Director Express For Big Data
Nov 21, 2024
May 6, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attac...Show more
A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect allocation of the enable/disable action button under the role-based access control code on an affected system. An attacker could exploit this vulnerability by authenticating as a read-only user and then updating the roles of other users to disable them. A successful exploit could allow the attacker to disable users, including administrative users.Show less
1Cisco
1Secure Firewall Management Center
Nov 26, 2024
May 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected d...Show more
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain unauthorized read access to sensitive data.Show less
1Cisco
1Firepower Threat Defense
Nov 21, 2024
May 6, 2020
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. T...Show more
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enabling the support tunnel, setting a key, and deriving the tunnel password. A successful exploit could allow the attacker to run any system command with root access on an affected device.Show less
1Cisco
13Asa 5505 Firmware
Asa 5510 FirmwareAsa 5512 X Firmware+10 more
Nov 21, 2024
May 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an a...Show more
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access list and denied in another. An attacker could exploit this vulnerability by sending crafted remote management traffic to the local IP address of an affected system. A successful exploit could allow the attacker to bypass the configured management access list policies, and traffic to the management interface would not be properly denied.Show less
1Redhat
4Jboss Enterprise Application Platform
Jboss Enterprise Application Platform Continuous DeliveryOpenshift Application Runtimes+1 more
Nov 21, 2024
May 4, 2020
N/A· v4
4.2 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead t...Show more
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.Show less
1Ui
2Unifi Cloud Key Gen2 Firmware
Unifi Cloud Key Gen2 Plus Firmware
Nov 21, 2024
May 2, 2020
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART).
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Apr 30, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the...Show more
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).Show less
1Inductiveautomation
1Ignition Gateway
Nov 21, 2024
Apr 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition...Show more
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a denial-of-service condition.Show less
1Prestashop
1Prestashop
Nov 21, 2024
Apr 20, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in 1.7.6.5.
1Prestashop
1Prestashop
Nov 21, 2024
Apr 20, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.
1Prestashop
1Prestashop
Nov 21, 2024
Apr 20, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.
1Prestashop
1Prestashop
Nov 21, 2024
Apr 20, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php...Show more
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/international/translations/ - admin-dev/index.php/improve/international/geolocation/ - admin-dev/index.php/improve/international/localization - admin-dev/index.php/configure/advanced/performance - admin-dev/index.php/sell/orders/delivery-slips/ - admin-dev/index.php?controller=AdminStatuses The problem is fixed in 1.7.6.5Show less
1Mcafee
1Endpoint Security
Nov 21, 2024
Apr 15, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attacker...Show more
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.Show less
1Cisco
1Webex Meetings Server
Nov 21, 2024
Apr 13, 2020
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes w...Show more
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this vulnerability by using the host role to share files within the Multimedia sharing feature and convincing a former room host to view that file. A warning dialog normally appears cautioning users before the file is displayed; however, the former host would not see that warning dialog, and any shared multimedia would be rendered within the user's browser. The attacker could leverage this behavior to conduct additional attacks by including malicious files within a targeted room host's browser window.Show less
1Cisco
1Webex Business Suite 39
Nov 21, 2024
Apr 13, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper validation of host h...Show more
Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper validation of host header values. An attacker with a privileged network position, either a man-in-the-middle or by intercepting wireless network traffic, could exploit this vulnerability to manipulate header values sent by a client to the affected application. The attacker could cause the application to use input from the header to redirect a user from the Cisco Webex Meetings Online site to an arbitrary site of the attacker's choosing.Show less
1Mh Wikibot Project
1Mh Wikibot
Nov 21, 2024
Apr 7, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access the steward commands on the IRC interface by impersonating the Nickname used by a privileged user as n...Show more
MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access the steward commands on the IRC interface by impersonating the Nickname used by a privileged user as no check was made to see if they were logged in. The issue has been fixed in commit 23d9d5b0a59667a5d6816fdabb960b537a5f9ed1.Show less
1Advantech
1Webaccess
Nov 21, 2024
Apr 1, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Nov 21, 2024
Mar 20, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
1Mcafee
1Agent
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility.