CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 21 of 38
- CVE-2021-36097MEDIUMCVSS 3.5EG 4.32021-10-18
Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.…
- CVE-2021-36129MEDIUMCVSS 4.3EG 4.32021-07-02
An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage…
- CVE-2021-36133HIGHCVSS 7.1EG 7.12021-12-07
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. T…
- CVE-2021-36279HIGHCVSS 7.8EG 7.82021-08-16
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information abo…
- CVE-2021-36280HIGHCVSS 7.8EG 7.82021-08-16
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information abo…
- CVE-2021-36281HIGHCVSS 7.5EG 7.52021-08-16
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can potentially exploit this vulnerability to escalate privileges.
- CVE-2021-36290MEDIUMCVSS 6.4EG 6.72022-04-08
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges.
- CVE-2021-3631MEDIUMCVSS 6.3EG 6.32022-03-02
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The high…
- CVE-2021-36934CRITICALCVSS 7.8EG 9.0⚠ KEV2021-07-22
<p>An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulner…
- CVE-2021-37058MEDIUMCVSS 5.3EG 5.32021-12-07
There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user's nickname is maliciously tampered with.
- CVE-2021-3706HIGHCVSS 7.5EG 7.52021-09-15
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
- CVE-2021-37207HIGHCVSS 7.8EG 7.82021-11-09
A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to…
- CVE-2021-37304HIGHCVSS 7.5EG 7.52023-02-03
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
- CVE-2021-37305HIGHCVSS 7.5EG 7.52023-02-03
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
- CVE-2021-37306HIGHCVSS 7.5EG 7.52023-02-03
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
- CVE-2021-37364HIGHCVSS 7.8EG 7.82021-10-26
OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located i…
- CVE-2021-3747HIGHCVSS 8.8EG 8.82021-10-01
The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.
- CVE-2021-37841HIGHCVSS 7.8EG 7.82021-08-12
Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V is…
- CVE-2021-38085HIGHCVSS 7.8EG 7.82021-08-11
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYST…
- CVE-2021-38154HIGHCVSS 7.5EG 7.52021-08-29
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to se…
- CVE-2021-38289HIGHCVSS 8.8EG 8.82022-07-12
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impa…
- CVE-2021-38475HIGHCVSS 7.3EG 8.82021-10-22
The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.
- CVE-2021-38483MEDIUMCVSS 6.0EG 6.72022-04-20
The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the binary and modify files to gain privilege escalation.
- CVE-2021-38557HIGHCVSS 8.8EG 8.82021-08-24
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data accou…
- CVE-2021-38590MEDIUMCVSS 5.5EG 5.52021-08-11
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
- CVE-2021-38879MEDIUMCVSS 5.3EG 5.32022-06-24
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitiv…
- CVE-2021-39210MEDIUMCVSS 6.5EG 6.52021-09-15
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal t…
- CVE-2021-39235MEDIUMCVSS 6.5EG 6.52021-11-19
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
- CVE-2021-39409CRITICALCVSS 9.8EG 9.82022-06-24
A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without needing to be authenticated.
- CVE-2021-39621HIGHCVSS 7.8EG 7.82022-01-14
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interactio…
- CVE-2021-39627HIGHCVSS 7.8EG 7.82022-01-14
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interactio…
- CVE-2021-39868MEDIUMCVSS 4.3EG 4.32021-10-04
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
- CVE-2021-39889MEDIUMCVSS 4.3EG 4.32021-10-05
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branc…
- CVE-2021-39992HIGHCVSS 7.8EG 7.82022-02-09
There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2021-40066MEDIUMCVSS 5.3EG 5.32021-09-16
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership setting…
- CVE-2021-40067MEDIUMCVSS 6.8EG 6.82021-09-16
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read a…
- CVE-2021-40101HIGHCVSS 7.2EG 7.22021-11-30
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
- CVE-2021-40331HIGHCVSS 8.1EG 8.12023-05-05
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is …
- CVE-2021-40343HIGHCVSS 7.8EG 7.82021-10-26
An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.
- CVE-2021-40649MEDIUMCVSS 6.5EG 6.52022-06-14
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
- CVE-2021-41091MEDIUMCVSS 6.3EG 6.32021-10-04
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted pe…
- CVE-2021-41170CRITICALCVSS 9.8EG 9.82021-11-08
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue a…
- CVE-2021-41589CRITICALCVSS 9.8EG 9.82021-10-27
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anon…
- CVE-2021-41802LOWCVSS 2.9EG 2.92021-10-08
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed i…
- CVE-2021-41834MEDIUMCVSS 5.3EG 6.52022-05-23
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to impro…
- CVE-2021-41974CRITICALCVSS 9.1EG 9.12021-10-08
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.
- CVE-2021-4199HIGHCVSS 7.8EG 7.82022-03-07
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote …
- CVE-2021-42115HIGHCVSS 8.1EG 8.12021-11-30
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via ste…
- CVE-2021-42309HIGHCVSS 8.8EG 8.82021-12-15
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2021-42562HIGHCVSS 8.1EG 8.12022-01-12
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →