← Back
CWE-602

148 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Client-Side Enforcement of Server-Side Security

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

JSON object

Loading...

CVEs (148)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-2022-004.
1Ibm
2Robotic Process Automation
Robotic Process Automation For Cloud Pak
Jun 17, 2026
Jan 18, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user...Show more
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side security enforcement.Show less
-
-
Jun 17, 2026
Dec 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.
1Ivanti
1Connect Secure
Jun 17, 2026
Dec 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
1Ethyca
1Fides
Jun 17, 2026
Nov 26, 2024
2.0 LOW· v4
8.8 HIGH· v3
N/A· v2
Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side valid...Show more
Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces password complexity requirements, direct API calls can circumvent these checks, enabling the creation of accounts with passwords as short as a single character. When an email messaging provider is enabled and a new user account is created in the system, an invite email containing a special link is sent to the new user's email address. This link directs the new user to a page where they can set their initial password. While the user interface implements password complexity checks, these validations are only performed client-side. The underlying `/api/v1/user/accept-invite` API endpoint does not implement the same password policy validations. This vulnerability allows an invited user to set an extremely weak password for their own account during the initial account setup process. Therefore that specific user's account can be compromised easily by an attacker guessing or brute forcing the password. The vulnerability has been patched in Fides version `2.50.0`. Users are advised to upgrade to this version or later to secure their systems against this threat. There are no known workarounds for this vulnerability.Show less
-
-
Jun 17, 2026
Nov 26, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis has released patched vers...Show more
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.Show less
1Fortinet
3Fortianalyzer
Fortianalyzer Big DataFortimanager
Jun 17, 2026
Nov 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 t...Show more
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Nov 6, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions. This vulnerability is due...Show more
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions. This vulnerability is due to lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload files to a location that should be restricted. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.Show less
1Ibm
1Business Automation Workflow
Jun 17, 2026
Sep 18, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation.
1Ivanti
1Workspace Control
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
1Cyberark
1Identity
Jun 17, 2026
Aug 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
-
-
Jun 17, 2026
Jul 29, 2024
N/A· v4
3.5 LOW· v3
N/A· v2
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, s...Show more
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent version of this firmware, PC42 Printer Firmware Version 20.6 T10.20.060398.Show less
1Siemens
1Sinema Remote Connect Server
Jun 17, 2026
Jul 9, 2024
7.1 HIGH· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privileg...Show more
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges.Show less
1Fortinet
1Fortiportal
Jun 17, 2026
Jun 3, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.
1Wpmet
1Wp Ultimate Review
Jun 17, 2026
May 17, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
-
-
Jun 17, 2026
May 17, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.
-
-
Jun 17, 2026
May 17, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.
1Fortinet
1Fortisandbox
Jun 17, 2026
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
1Deltaww
1Diaenergie
Jun 17, 2026
Mar 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
1Userproplugin
1Userpro
Jun 17, 2026
Feb 5, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the 'Disabled registration' Membership...Show more
The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the plugin's General settings. This makes it possible for unauthenticated attackers to register an account even when account registration has been disabled by an administrator.Show less