CWE-284— Improper Access Control
4,211 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 6 of 85
- CVE-2019-10130MEDIUMCVSS 4.3EG 4.32019-07-30
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, suc…
- CVE-2019-10138HIGHCVSS 8.8EG 8.82019-07-30
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA token…
- CVE-2019-10161HIGHCVSS 7.8EG 7.82019-07-30
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd proces…
- CVE-2019-10166HIGHCVSS 7.8EG 7.82019-08-02
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed sa…
- CVE-2019-10167HIGHCVSS 7.8EG 7.82019-08-02
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that pro…
- CVE-2019-10168HIGHCVSS 7.8EG 7.82019-08-02
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libv…
- CVE-2019-10175MEDIUMCVSS 6.5EG 6.52019-06-28
A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the s…
- CVE-2019-10187MEDIUMCVSS 4.3EG 4.32019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
- CVE-2019-10188MEDIUMCVSS 4.3EG 4.32019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
- CVE-2019-10189MEDIUMCVSS 4.3EG 4.32019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
- CVE-2019-10200HIGHCVSS 7.2EG 7.22021-03-19
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nod…
- CVE-2019-10925HIGHCVSS 7.1EG 7.12019-06-12
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by sending specially crafted requests to the integrated webserver. The security vulnerability can be e…
- CVE-2019-10938CRITICALCVSS 9.8EG 9.82019-08-02
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1)…
- CVE-2019-10950CRITICALCVSS 9.8EG 9.82019-04-30
Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits t…
- CVE-2019-10962MEDIUMCVSS 5.3EG 5.32019-06-13
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Work…
- CVE-2019-10964HIGHCVSS 7.1EG 7.12019-06-28
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not pro…
- CVE-2019-10970CRITICALCVSS 9.8EG 9.82019-07-11
In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Disp…
- CVE-2019-11634CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-22
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
- CVE-2019-11780HIGHCVSS 8.1EG 8.12019-12-19
Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to priv…
- CVE-2019-11782MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.
- CVE-2019-11783MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
- CVE-2019-11784MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party…
- CVE-2019-11785MEDIUMCVSS 4.3EG 4.32020-12-22
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given acce…
- CVE-2019-11786MEDIUMCVSS 4.3EG 4.32020-12-22
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.
- CVE-2019-11892HIGHCVSS 8.0EG 8.02019-05-29
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggering and restoring ba…
- CVE-2019-11894MEDIUMCVSS 5.7EG 5.72019-05-29
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adver…
- CVE-2019-11895MEDIUMCVSS 5.3EG 5.32019-05-29
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In…
- CVE-2019-11896HIGHCVSS 7.1EG 7.12019-05-29
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to e…
- CVE-2019-11899HIGHCVSS 7.5EG 7.52019-09-12
An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch Access Professional Edition (APE) 3.8, client installations need to be authorized by the …
- CVE-2019-12627HIGHCVSS 7.5EG 7.52019-08-21
A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to in…
- CVE-2019-12648HIGHCVSS 8.8EG 8.82019-09-25
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability i…
- CVE-2019-12670MEDIUMCVSS 6.7EG 6.72019-09-25
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the namespace container protections on an affected device. The vulnerability is due to insufficien…
- CVE-2019-13028HIGHCVSS 8.8EG 8.82019-06-28
An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files via a crafted HTML …
- CVE-2019-13656CRITICALCVSS 9.8EG 9.82019-09-06
An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.
- CVE-2019-13919MEDIUMCVSS 4.3EG 4.32019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could b…
- CVE-2019-14838MEDIUMCVSS 4.9EG 4.92019-10-14
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
- CVE-2019-14902MEDIUMCVSS 5.4EG 5.42020-01-21
There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be take…
- CVE-2019-15068CRITICALCVSS 9.8EG 9.82019-09-25
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.
- CVE-2019-15255MEDIUMCVSS 6.5EG 6.52020-01-26
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability e…
- CVE-2019-15260CRITICALCVSS 9.8EG 9.82019-10-16
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access contro…
- CVE-2019-15589HIGHCVSS 8.8EG 8.82019-12-18
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
- CVE-2019-15590HIGHCVSS 7.5EG 7.52020-01-28
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elastics…
- CVE-2019-15591MEDIUMCVSS 6.5EG 6.52019-12-18
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
- CVE-2019-15615MEDIUMCVSS 6.1EG 6.12020-02-04
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
- CVE-2019-15956HIGHCVSS 8.8EG 8.82019-11-26
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability…
- CVE-2019-15967MEDIUMCVSS 4.4EG 4.42019-11-26
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, local attacker to enable audio recording without notifying users. The vulnerability is due to the presence…
- CVE-2019-15998MEDIUMCVSS 5.3EG 5.32019-11-26
A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected…
- CVE-2019-15999MEDIUMCVSS 6.3EG 6.32020-01-06
A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected de…
- CVE-2019-1601HIGHCVSS 7.8EG 7.82019-03-08
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file. The vulnerability is due to a failure to impose strict files…
- CVE-2019-1619CRITICALCVSS 9.8EG 9.82019-06-27
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an a…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →