← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
May 6, 2026
Mar 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call t...Show more
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.Show less
1Google
1Chrome
May 6, 2026
Mar 6, 2016
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restricti...Show more
extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.Show less
1Hp
71000 Series Firmware
700 Series Firmware800 Series Firmware+4 more
May 6, 2026
Mar 4, 2016
N/A· v4
7.9 HIGH· v3
5.4 MEDIUM· v2
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.
1Ibm
1Infosphere Information Server
May 6, 2026
Mar 3, 2016
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
1Schneider Electric
2Struxureware Building Operations Automation Server As P Firmware
Struxureware Building Operations Automation Server As Firmware
May 6, 2026
Mar 2, 2016
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minim...Show more
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.Show less
1Ibm
1Websphere Commerce
May 6, 2026
Feb 29, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.
1Advantech
2Vesp211 232 Firmware
Vesp211 Eu Firmware
May 6, 2026
Feb 21, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to...Show more
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.Show less
1Rubyonrails
2Rails
Ruby On Rails
May 6, 2026
Feb 16, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly...Show more
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.Show less
1Ibm
1Qradar Security Information And Event Manager
May 6, 2026
Feb 15, 2016
N/A· v4
4.4 MEDIUM· v3
3.5 LOW· v2
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by readin...Show more
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.Show less
1Cisco
1Email Security Appliance Firmeware
May 6, 2026
Feb 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malfor...Show more
The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malformed e-mail message containing an encoded file, aka Bug ID CSCux45338.Show less
1Djangoproject
1Django
May 6, 2026
Feb 8, 2016
N/A· v4
5.5 MEDIUM· v3
6.0 MEDIUM· v2
Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects...Show more
Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.Show less
1Atlassian
1Bamboo
May 6, 2026
Feb 8, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agent...Show more
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.Show less
5Cisco
SamsungSun+2 more
5Gs1900 10hp Firmware
Keymouse FirmwareNx Os+2 more
May 6, 2026
Feb 7, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote a...Show more
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.Show less
1Cisco
2Asa Cx Context Aware Security Software
Prime Security Manager
May 6, 2026
Feb 7, 2016
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passw...Show more
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.Show less
1Kubernetes
1Kubernetes
May 6, 2026
Feb 3, 2016
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
1Janrain
1Php Openid
May 6, 2026
Feb 1, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers...Show more
examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header.Show less
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
6.1 MEDIUM· v3
2.9 LOW· v2
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within...Show more
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.Show less
1Cisco
1Identity Services Engine Software
May 6, 2026
Jan 23, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.
4Canonical
OpensuseOracle+1 more
5Enterprise Linux
LeapMysql+2 more
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
1Mozilla
1Firefox Os
May 6, 2026
Jan 9, 2016
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guess...Show more
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.Show less