← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
1Ibm
1Tivoli Directory Server
May 6, 2026
Jun 28, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows lo...Show more
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive information or possibly have unspecified other impact via a (1) download or (2) upload action.Show less
1Igreks
3Milkystep Light
Milkystep ProfessionalMilkystep Professional Oem
May 6, 2026
Jun 13, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrativ...Show more
The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and CVE-2015-2958.Show less
1Zohocorp
1Manageengine Netflow Analyzer
May 6, 2026
Jun 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
1Zohocorp
1Manageengine Netflow Analyzer
May 6, 2026
Jun 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest r...Show more
Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role.Show less
1Beckhoff
1Ipc Diagnostics
May 6, 2026
Jun 8, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have uns...Show more
Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi.Show less
2Apache
Debian
2Debian Linux
Tomcat
May 6, 2026
Jun 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessibl...Show more
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.Show less
1Sensiolabs
1Symfony
May 6, 2026
Jun 2, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attri...Show more
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.Show less
1Moodle
1Moodle
May 6, 2026
Jun 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories v...Show more
mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.Show less
1Ibm
1Powervc
May 6, 2026
May 30, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary dat...Show more
IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.Show less
1Cisco
1Anyconnect Secure Mobility Client
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecified commands, aka Bug ID CSCut05797.
1Ibm
1Infosphere Information Server
May 6, 2026
May 25, 2015
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors.
1Cisco
2Telepresence Tc Software
Telepresence Te Software
May 6, 2026
May 25, 2015
N/A· v4
N/A· v3
8.3 HIGH· v2
Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local network and allows p...Show more
Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local network and allows physically proximate attackers to obtain root privileges via unspecified vectors, aka Bug ID CSCub67651.Show less
1Huawei
1E587 Mobile Wifi Firmware
May 6, 2026
May 21, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
Huawei E587 Mobile WiFi with firmware before 11.203.30.00.00 allows remote attackers to bypass authentication, change configurations, send messages, and cause a denial of service (device restart) via unspecified vectors.
2Debian
Google
2Chrome
Debian Linux
May 6, 2026
May 20, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that append...Show more
core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element, related to the insert and executeReparentTask functions.Show less
1Ibm
1Websphere Application Server
May 6, 2026
May 20, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a managem...Show more
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.Show less
2Canonical
Module Signature Project
2Module Signature
Ubuntu Linux
May 6, 2026
May 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
1Proftpd
1Proftpd
May 6, 2026
May 18, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
1Stunnel
1Stunnel
May 6, 2026
May 14, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.
3Adobe
AppleMicrosoft
4Acrobat
Acrobat ReaderMac Os X+1 more
May 6, 2026
May 13, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than...Show more
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3073.Show less