CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 13 of 23
- CVE-2022-22334MEDIUMCVSS 4.3EG 4.32022-08-01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of which they should not have access. IBM X-Force ID: 219391.
- CVE-2022-22414MEDIUMCVSS 5.5EG 5.52022-06-20
IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026.
- CVE-2022-22442MEDIUMCVSS 6.5EG 6.52022-11-03
"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427."
- CVE-2022-22480HIGHCVSS 7.5EG 7.52022-10-07
IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889.
- CVE-2022-22483MEDIUMCVSS 6.5EG 6.52022-09-13
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM…
- CVE-2022-22494MEDIUMCVSS 5.3EG 5.32022-06-30
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in fu…
- CVE-2022-22515HIGHCVSS 8.1EG 8.12022-04-07
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
- CVE-2022-22579HIGHCVSS 7.8EG 7.82022-03-18
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciousl…
- CVE-2022-22583MEDIUMCVSS 5.5EG 5.52022-03-18
A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access restricted files.
- CVE-2022-22598LOWCVSS 3.3EG 3.32022-03-18
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.
- CVE-2022-22622MEDIUMCVSS 4.6EG 4.62022-03-18
This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
- CVE-2022-22652MEDIUMCVSS 6.1EG 6.12022-03-18
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical …
- CVE-2022-22662MEDIUMCVSS 6.5EG 6.52022-05-26
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
- CVE-2022-22711MEDIUMCVSS 5.7EG 6.72022-07-12
Windows BitLocker Information Disclosure Vulnerability
- CVE-2022-22716MEDIUMCVSS 5.5EG 5.52022-02-09
Microsoft Excel Information Disclosure Vulnerability
- CVE-2022-22732HIGHCVSS 3.9EG 7.52023-01-30
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. …
- CVE-2022-22783HIGHCVSS 6.5EG 7.52022-04-28
A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a pass…
- CVE-2022-22961MEDIUMCVSS 5.3EG 5.32022-04-13
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Suc…
- CVE-2022-23118HIGHCVSS 8.8EG 8.82022-01-12
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke…
- CVE-2022-23163MEDIUMCVSS 4.7EG 5.52022-04-12
Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious user could potentially exploit this vulnerability, leading to denial of service/data unavailability.
- CVE-2022-23252MEDIUMCVSS 5.5EG 5.52022-02-09
Microsoft Office Information Disclosure Vulnerability
- CVE-2022-23254MEDIUMCVSS 4.9EG 4.92022-02-09
Microsoft Power BI Information Disclosure Vulnerability
- CVE-2022-23317HIGHCVSS 7.5EG 7.52022-02-15
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
- CVE-2022-23331HIGHCVSS 8.8EG 8.82022-02-08
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
- CVE-2022-23345HIGHCVSS 7.5EG 7.52022-03-21
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
- CVE-2022-23690MEDIUMCVSS 5.3EG 5.32022-09-06
A vulnerability in the web-based management interface of AOS-CX could allow a remote unauthenticated attacker to fingerprint the exact version AOS-CX running on the switch. This allows an attacker to retrieve information which could be use…
- CVE-2022-2370MEDIUMCVSS 6.5EG 6.52022-08-01
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
- CVE-2022-23825MEDIUMCVSS 6.5EG 6.52022-07-14
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
- CVE-2022-23835HIGHCVSS 8.1EG 8.12022-02-25
The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design…
- CVE-2022-23856MEDIUMCVSS 5.3EG 5.32022-01-24
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI.
- CVE-2022-23950HIGHCVSS 7.5EG 7.52022-09-21
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.
- CVE-2022-2403MEDIUMCVSS 6.5EG 6.52022-09-01
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or servi…
- CVE-2022-24032MEDIUMCVSS 5.3EG 5.32022-01-30
Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a different error message when the username is valid.
- CVE-2022-24074CRITICALCVSS 9.8EG 9.82022-03-17
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
- CVE-2022-2408MEDIUMCVSS 4.3EG 4.32022-07-14
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
- CVE-2022-24139HIGHCVSS 7.8EG 7.82022-07-06
In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named p…
- CVE-2022-24309HIGHCVSS 6.8EG 8.12022-03-08
A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtime V9 (All versions < V9.13 only with Runtime Custom Setting *DataStorage.UseNewQueryHandler* set …
- CVE-2022-24336MEDIUMCVSS 5.3EG 5.32022-02-25
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.
- CVE-2022-24411HIGHCVSS 7.8EG 7.82022-04-12
Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. …
- CVE-2022-24446MEDIUMCVSS 4.3EG 4.32022-03-01
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
- CVE-2022-24503MEDIUMCVSS 5.4EG 5.42022-03-09
Remote Desktop Protocol Client Information Disclosure Vulnerability
- CVE-2022-24522MEDIUMCVSS 6.5EG 6.52022-03-09
Skype Extension for Chrome Information Disclosure Vulnerability
- CVE-2022-24742MEDIUMCVSS 5.0EG 5.02022-03-14
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A worka…
- CVE-2022-24747MEDIUMCVSS 6.3EG 6.32022-03-09
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the s…
- CVE-2022-2479MEDIUMCVSS 4.3EG 4.32022-07-28
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file direc…
- CVE-2022-24823MEDIUMCVSS 5.5EG 5.52022-05-06
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are us…
- CVE-2022-24900CRITICALCVSS 9.9EG 9.92022-04-29
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untruste…
- CVE-2022-24913MEDIUMCVSS 5.5EG 5.52023-01-12
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, …
- CVE-2022-24975HIGHCVSS 7.5EG 7.52022-02-11
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation wit…
- CVE-2022-24986HIGHCVSS 7.8EG 7.82022-02-26
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling t…
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →