CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 6 of 23
- CVE-2021-20416MEDIUMCVSS 5.3EG 5.32021-07-07
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive in…
- CVE-2021-20461MEDIUMCVSS 6.5EG 6.52021-06-30
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the applicat…
- CVE-2021-20488MEDIUMCVSS 6.5EG 6.52021-06-16
IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configur…
- CVE-2021-20500MEDIUMCVSS 4.4EG 4.42021-07-15
IBM Security Verify Access Docker 10.0.0 could reveal highly sensitive information to a local privileged user. IBM X-Force ID: 197980.
- CVE-2021-20551LOWCVSS 3.3EG 3.32022-06-24
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 199149.
- CVE-2021-20755MEDIUMCVSS 4.3EG 4.32021-08-18
Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.
- CVE-2021-20756MEDIUMCVSS 4.3EG 4.32021-08-18
Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.
- CVE-2021-20763MEDIUMCVSS 4.3EG 4.32021-08-18
Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege.
- CVE-2021-20790CRITICALCVSS 9.6EG 9.62021-09-17
Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execute an arbitrary command or code via unspecified vectors.
- CVE-2021-20832MEDIUMCVSS 5.3EG 5.32021-10-13
InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerability which may lead to information disclosure only when it works with the body composition analyzer InBody Dial. This m…
- CVE-2021-20999CRITICALCVSS 9.4EG 9.82021-05-13
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manip…
- CVE-2021-21210MEDIUMCVSS 6.5EG 6.52021-04-26
Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially access local UDP ports via a crafted HTML page.
- CVE-2021-21290MEDIUMCVSS 6.2EG 6.22021-02-08
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like …
- CVE-2021-21334MEDIUMCVSS 6.3EG 6.32021-03-10
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CR…
- CVE-2021-21382HIGHCVSS 8.6EG 8.62021-06-11
Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In t…
- CVE-2021-21428CRITICALCVSS 9.3EG 9.32021-05-10
Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folde…
- CVE-2021-21430MEDIUMCVSS 6.2EG 6.22021-05-10
OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure …
- CVE-2021-21878MEDIUMCVSS 4.9EG 4.92021-12-22
A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion. An attacker can m…
- CVE-2021-22007MEDIUMCVSS 5.5EG 5.52021-09-23
The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.
- CVE-2021-22008HIGHCVSS 7.5EG 7.52021-09-23
The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message t…
- CVE-2021-22009HIGHCVSS 7.5EG 7.52021-09-23
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due …
- CVE-2021-22012HIGHCVSS 7.5EG 7.52021-09-23
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive …
- CVE-2021-22034HIGHCVSS 7.5EG 7.52021-10-21
Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.
- CVE-2021-22044HIGHCVSS 7.5EG 7.52021-10-28
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corr…
- CVE-2021-22047MEDIUMCVSS 5.3EG 5.32021-10-28
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally expo…
- CVE-2021-22118HIGHCVSS 7.8EG 7.82021-05-27
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user c…
- CVE-2021-22146HIGHCVSS 7.5EG 7.52021-07-21
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elastic…
- CVE-2021-22215HIGHCVSS 7.5EG 7.52021-06-08
An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects
- CVE-2021-22252MEDIUMCVSS 6.5EG 6.52021-08-23
A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers
- CVE-2021-22385HIGHCVSS 7.8EG 7.82021-08-10
A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
- CVE-2021-22420HIGHCVSS 7.8EG 7.82021-08-03
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
- CVE-2021-22446HIGHCVSS 7.5EG 7.52021-08-02
There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
- CVE-2021-22454MEDIUMCVSS 5.5EG 5.52021-10-28
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
- CVE-2021-22468LOWCVSS 3.3EG 3.32021-10-28
A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage.
- CVE-2021-22488HIGHCVSS 7.5EG 7.52021-10-28
There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tamper with the files restored from backups.
- CVE-2021-22525MEDIUMCVSS 5.5EG 5.52021-09-02
This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1
- CVE-2021-22539HIGHCVSS 8.2EG 8.22021-04-16
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker is able to execute an…
- CVE-2021-22549HIGHCVSS 6.5EG 7.82021-06-08
An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c
- CVE-2021-22550MEDIUMCVSS 6.5EG 6.52021-06-08
An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd2…
- CVE-2021-22568HIGHCVSS 8.8EG 8.82021-12-09
When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an atta…
- CVE-2021-22572MEDIUMCVSS 5.5EG 5.52022-03-29
On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive infor…
- CVE-2021-22785HIGHCVSS 7.5EG 7.52022-02-11
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon…
- CVE-2021-22869CRITICALCVSS 9.8EG 9.82021-09-24
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access contro…
- CVE-2021-22897MEDIUMCVSS 5.3EG 5.32021-06-11
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a singl…
- CVE-2021-22957HIGHCVSS 8.8EG 8.82021-11-24
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s …
- CVE-2021-23034HIGHCVSS 7.5EG 7.52021-09-14
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.…
- CVE-2021-23173MEDIUMCVSS 2.6EG 4.32022-01-10
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.
- CVE-2021-23263HIGHCVSS 5.9EG 7.52021-12-02
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
- CVE-2021-23264HIGHCVSS 8.1EG 8.12021-12-02
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
- CVE-2021-23391HIGHCVSS 7.3EG 7.32021-06-07
This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →