← Back
CWE-284

7,447 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,447)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Infosphere Information Server
May 6, 2026
Mar 3, 2016
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
1Schneider Electric
2Struxureware Building Operations Automation Server As P Firmware
Struxureware Building Operations Automation Server As Firmware
May 6, 2026
Mar 2, 2016
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minim...Show more
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.Show less
1Ibm
1Websphere Commerce
May 6, 2026
Feb 29, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.
1Advantech
2Vesp211 232 Firmware
Vesp211 Eu Firmware
May 6, 2026
Feb 21, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to...Show more
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.Show less
1Rubyonrails
2Rails
Ruby On Rails
May 6, 2026
Feb 16, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly...Show more
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.Show less
1Ibm
1Qradar Security Information And Event Manager
May 6, 2026
Feb 15, 2016
N/A· v4
4.4 MEDIUM· v3
3.5 LOW· v2
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by readin...Show more
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.Show less
1Cisco
1Email Security Appliance Firmeware
May 6, 2026
Feb 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malfor...Show more
The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malformed e-mail message containing an encoded file, aka Bug ID CSCux45338.Show less
1Djangoproject
1Django
May 6, 2026
Feb 8, 2016
N/A· v4
5.5 MEDIUM· v3
6.0 MEDIUM· v2
Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects...Show more
Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.Show less
1Atlassian
1Bamboo
May 6, 2026
Feb 8, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agent...Show more
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.Show less
5Cisco
SamsungSun+2 more
5Gs1900 10hp Firmware
Keymouse FirmwareNx Os+2 more
May 6, 2026
Feb 7, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote a...Show more
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.Show less
1Cisco
2Asa Cx Context Aware Security Software
Prime Security Manager
May 6, 2026
Feb 7, 2016
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passw...Show more
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.Show less
1Kubernetes
1Kubernetes
May 6, 2026
Feb 3, 2016
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
1Janrain
1Php Openid
May 6, 2026
Feb 1, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers...Show more
examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header.Show less
1Lenovo
1Shareit
May 6, 2026
Jan 26, 2016
N/A· v4
6.1 MEDIUM· v3
2.9 LOW· v2
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within...Show more
The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.Show less
1Cisco
1Identity Services Engine Software
May 6, 2026
Jan 23, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.
4Canonical
OpensuseOracle+1 more
5Enterprise Linux
LeapMysql+2 more
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
1Mozilla
1Firefox Os
May 6, 2026
Jan 9, 2016
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guess...Show more
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.Show less
1Vmware
4Esxi
FusionPlayer+1 more
May 6, 2026
Jan 9, 2016
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS...Show more
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors.Show less
1Hp
1Ucmdb Browser
May 6, 2026
Jan 8, 2016
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.
1Ibm
13Change And Configuration Management Database
Maximo Asset ManagementMaximo Asset Management Essentials+10 more
May 6, 2026
Jan 3, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartClo...Show more
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended access restrictions and establish a login session by entering an expired password.Show less