CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
7,281 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 3 of 146
- CVE-2015-0104HIGHCVSS 8.8EG 8.82017-04-24
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7…
- CVE-2015-0110MEDIUMCVSS 6.5EG 6.52017-09-15
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the execu…
- CVE-2015-0150CRITICALCVSS 9.8EG 9.82018-04-12
The remote administration UI in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to bypass intended access restrictions via unspecified vectors.
- CVE-2015-0660HIGHCVSS v2 7.2EG 7.22015-03-14
Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSphere controller administrative privileges, aka Bug ID CSCus611…
- CVE-2015-0667MEDIUMCVSS v2 5.0EG 5.02015-03-18
The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attackers to bypass intended restrictions on local-network device access via crafted SSH packets, aka Bug ID CSCut14855.
- CVE-2015-0820LOWCVSS v2 2.6EG 2.62015-02-25
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure E…
- CVE-2015-0926MEDIUMCVSS v2 6.8EG 6.82015-02-01
Labtech before 100.237 on Linux uses world-writable permissions for root-executed scripts, which allows local users to gain privileges by modifying a script file.
- CVE-2015-0929HIGHCVSS v2 10.0EG 10.02015-02-03
time.htm in the web interface on SerVision HVG Video Gateway devices with firmware before 2.2.26a78 allows remote attackers to bypass authentication and obtain administrative access by leveraging a cookie received in an HTTP response.
- CVE-2015-1000009CRITICALCVSS 9.1EG 9.12016-10-06
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
- CVE-2015-1000010HIGHCVSS 7.5EG 7.52016-10-06
Remote file download in simple-image-manipulator v1.0 wordpress plugin
- CVE-2015-10057CRITICALCVSS 4.6EG 9.82023-01-16
A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file inc/class.securelogin.php of the component Password Reset Handler. The…
- CVE-2015-1307MEDIUMCVSS v2 4.3EG 4.32015-01-26
plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.
- CVE-2015-1336HIGHCVSS 7.8EG 7.82017-09-28
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
- CVE-2015-1376MEDIUMCVSS v2 4.0EG 4.02015-01-28
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.
- CVE-2015-1464MEDIUMCVSS v2 6.4EG 6.42015-03-09
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
- CVE-2015-1631MEDIUMCVSS v2 5.0EG 5.02015-03-11
Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange Forged Meeting Request Spoofing Vulnerability."
- CVE-2015-1854HIGHCVSS 7.5EG 7.52017-09-19
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
- CVE-2015-1976MEDIUMCVSS 5.5EG 5.52017-02-08
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
- CVE-2015-1985MEDIUMCVSS 5.6EG 5.62016-01-03
The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.
- CVE-2015-2008MEDIUMCVSS 4.4EG 4.42016-02-15
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.
- CVE-2015-2107MEDIUMCVSS v2 6.8EG 6.82015-03-14
HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.
- CVE-2015-2172MEDIUMCVSS v2 6.5EG 6.52015-03-30
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
- CVE-2015-2559LOWCVSS v2 3.5EG 3.52015-03-25
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.
- CVE-2015-2687MEDIUMCVSS 4.7EG 4.72017-08-09
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
- CVE-2015-2692CRITICALCVSS 10.0EG 10.02017-06-08
AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.
- CVE-2015-2792HIGHCVSS v2 7.5EG 7.52015-03-30
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an act…
- CVE-2015-2816HIGHCVSS v2 7.5EG 7.52015-04-01
The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted request, aka SAP Security Note 2134905.
- CVE-2015-2841MEDIUMCVSS v2 5.0EG 5.02015-04-03
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.
- CVE-2015-3163MEDIUMCVSS 4.3EG 4.32017-09-06
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes resp…
- CVE-2015-3295MEDIUMCVSS 5.3EG 5.32017-06-07
markdown-it before 4.1.0 does not block data: URLs.
- CVE-2015-3302HIGHCVSS 7.5EG 7.52017-12-29
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mech…
- CVE-2015-3306HIGHCVSS v2 10.0EG 10.02015-05-18
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
- CVE-2015-3653HIGHCVSS 7.2EG 7.22017-08-29
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating system and consequently cause a denial of service or gain pr…
- CVE-2015-3654HIGHCVSS 7.2EG 7.22017-08-29
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different vulnerability than CVE-2015-4649.
- CVE-2015-3657HIGHCVSS 7.2EG 7.22017-08-29
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Admin" privileges via unspecified vectors.
- CVE-2015-3840MEDIUMCVSS 5.5EG 5.52017-06-27
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
- CVE-2015-3854HIGHCVSS 7.5EG 7.52016-08-07
packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.
- CVE-2015-3888HIGHCVSS 7.5EG 7.52018-01-12
Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.
- CVE-2015-4594CRITICALCVSS 9.8EG 9.82017-01-10
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.
- CVE-2015-4624HIGHCVSS 7.5EG 7.72017-03-31
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
- CVE-2015-4649HIGHCVSS 7.2EG 7.22017-08-29
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different vulnerability than CVE-2015-3654.
- CVE-2015-4902CRITICALCVSS 5.3EG 9.0⚠ KEV2015-10-22
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
- CVE-2015-5017MEDIUMCVSS 5.4EG 5.42016-01-03
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; an…
- CVE-2015-5207MEDIUMCVSS 5.3EG 5.32016-05-09
Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
- CVE-2015-5247MEDIUMCVSS 6.5EG 6.52016-04-14
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_sq…
- CVE-2015-5293MEDIUMCVSS 5.9EG 5.92017-08-24
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
- CVE-2015-5350HIGHCVSS 7.5EG 7.52018-03-19
In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations wit…
- CVE-2015-6023HIGHCVSS 7.3EG 7.32017-02-09
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. NOTE: this issue can be combined with CVE-201…
- CVE-2015-6317MEDIUMCVSS 6.5EG 6.52016-01-23
Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.
- CVE-2015-6550CRITICALCVSS 9.8EG 9.82016-05-07
bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows …
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →