CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,884 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 3 of 38
- CVE-2017-16631MEDIUMCVSS 6.5EG 6.52021-08-11
In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Direct Object Reference (IDOR) in the "Account Password Reset" functionality.
- CVE-2017-16638CRITICALCVSS 9.8EG 9.82017-11-06
The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a directory on which "chown" is called recursively by the OpenRC service script.
- CVE-2017-16659HIGHCVSS 7.8EG 7.82017-11-08
The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script.
- CVE-2017-16754MEDIUMCVSS 5.3EG 5.32017-11-10
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
- CVE-2017-16757HIGHCVSS 7.8EG 7.82017-11-09
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
- CVE-2017-16834HIGHCVSS 7.8EG 7.82017-11-16
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.
- CVE-2017-16882HIGHCVSS 7.8EG 7.82017-11-18
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local u…
- CVE-2017-16885CRITICALCVSS 9.8EG 9.82018-01-12
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenti…
- CVE-2017-16895HIGHCVSS 7.8EG 7.82017-12-01
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.
- CVE-2017-16928HIGHCVSS 7.8EG 7.82018-01-31
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.
- CVE-2017-16933HIGHCVSS 7.0EG 7.02017-11-24
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.
- CVE-2017-16945HIGHCVSS 7.8EG 7.82018-01-31
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.
- CVE-2017-1699LOWCVSS 3.3EG 3.32018-01-04
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID:…
- CVE-2017-1716LOWCVSS 3.3EG 3.32017-12-13
IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a local attacker due to improper permission settings. IBM X-Force ID: 134638.
- CVE-2017-17568HIGHCVSS 7.5EG 7.52017-12-13
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request.
- CVE-2017-17677HIGHCVSS 8.8EG 8.82021-05-19
BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code.
- CVE-2017-17867HIGHCVSS 8.8EG 8.82018-01-04
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located …
- CVE-2017-18225HIGHCVSS 7.8EG 7.82018-03-12
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access …
- CVE-2017-18226MEDIUMCVSS 5.5EG 5.52018-03-12
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a…
- CVE-2017-18284HIGHCVSS 7.1EG 7.12018-06-04
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification bef…
- CVE-2017-18285HIGHCVSS 7.1EG 7.12018-06-04
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a bur…
- CVE-2017-18348HIGHCVSS 7.0EG 7.02018-10-19
Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-root account to modify $SPLUNK_HOME/etc/splunk-launch.conf a…
- CVE-2017-18870MEDIUMCVSS 4.3EG 4.32020-06-19
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
- CVE-2017-18872MEDIUMCVSS 4.3EG 4.32020-06-19
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
- CVE-2017-18875MEDIUMCVSS 4.9EG 4.92020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
- CVE-2017-18876MEDIUMCVSS 4.9EG 4.92020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
- CVE-2017-18878MEDIUMCVSS 4.3EG 4.32020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
- CVE-2017-18886HIGHCVSS 8.8EG 8.82020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
- CVE-2017-18894HIGHCVSS 8.1EG 8.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
- CVE-2017-18896MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
- CVE-2017-18910MEDIUMCVSS 4.3EG 4.32020-06-19
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.
- CVE-2017-18916MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.
- CVE-2017-20148CRITICALCVSS 9.8EG 9.82022-09-20
In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.
- CVE-2017-20198CRITICALCVSS 9.3EG 9.32025-07-23
The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount configurations, attackers can deploy a container that mounts the host's root filesystem (/) wi…
- CVE-2017-2115MEDIUMCVSS 4.3EG 4.32017-04-28
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.
- CVE-2017-2290HIGHCVSS 8.8EG 8.82017-03-03
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users ar…
- CVE-2017-2590HIGHCVSS 8.1EG 8.12018-07-27
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delet…
- CVE-2017-2612MEDIUMCVSS 5.4EG 5.42018-05-15
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
- CVE-2017-3006HIGHCVSS 8.8EG 8.82017-04-12
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.
- CVE-2017-3166HIGHCVSS 7.8EG 7.82017-11-13
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a w…
- CVE-2017-4952HIGHCVSS 7.5EG 7.52018-05-02
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Succes…
- CVE-2017-5118MEDIUMCVSS 4.3EG 4.32017-10-27
Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security p…
- CVE-2017-5199HIGHCVSS 8.8EG 8.82017-03-24
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
- CVE-2017-5260HIGHCVSS 8.8EG 8.82017-12-20
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessibl…
- CVE-2017-5426MEDIUMCVSS 5.3EG 5.32018-06-11
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running fi…
- CVE-2017-5456CRITICALCVSS 9.8EG 9.82018-06-11
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < …
- CVE-2017-6104HIGHCVSS 7.5EG 7.52017-03-02
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
- CVE-2017-6338MEDIUMCVSS 6.5EG 6.52017-04-05
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Setting…
- CVE-2017-6356MEDIUMCVSS 5.3EG 5.32017-03-20
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors.
- CVE-2017-6928MEDIUMCVSS 5.3EG 5.32018-03-01
Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which on…
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →