CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
7,281 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 4 of 146
- CVE-2015-6552CRITICALCVSS 9.8EG 9.82016-05-07
The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x thro…
- CVE-2015-6862HIGHCVSS 8.4EG 8.42016-01-08
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.
- CVE-2015-6933MEDIUMCVSS 6.3EG 6.32016-01-09
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest…
- CVE-2015-7263HIGHCVSS 7.5EG 7.52017-04-10
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.
- CVE-2015-7265HIGHCVSS 7.5EG 7.52017-04-10
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
- CVE-2015-7315MEDIUMCVSS 5.9EG 5.92017-09-25
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of sit…
- CVE-2015-7473LOWCVSS 2.5EG 2.52016-06-26
runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.
- CVE-2015-7490LOWCVSS 3.1EG 3.12016-03-03
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
- CVE-2015-7494LOWCVSS 2.8EG 2.82017-02-08
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possib…
- CVE-2015-7545CRITICALCVSS 9.8EG 9.82016-04-13
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attacker…
- CVE-2015-7560MEDIUMCVSS 6.5EG 6.52016-03-13
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink,…
- CVE-2015-7577MEDIUMCVSS 5.3EG 5.32016-02-16
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certai…
- CVE-2015-7887HIGHCVSS 8.1EG 8.12017-08-07
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.
- CVE-2015-7895MEDIUMCVSS 5.5EG 5.52017-06-27
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- CVE-2015-7898MEDIUMCVSS 5.5EG 5.52017-06-27
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- CVE-2015-8008HIGHCVSS 7.5EG 7.52017-12-29
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.
- CVE-2015-8021MEDIUMCVSS 4.3EG 4.32016-04-12
Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 an…
- CVE-2015-8139MEDIUMCVSS 5.3EG 5.32017-01-30
ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecified vectors.
- CVE-2015-8140MEDIUMCVSS 4.8EG 4.82017-01-30
The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sniffing the network.
- CVE-2015-8275MEDIUMCVSS 5.5EG 5.52017-04-10
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files.
- CVE-2015-8284HIGHCVSS 8.8EG 8.82017-04-13
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
- CVE-2015-8307HIGHCVSS 7.8EG 7.82016-04-07
The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S …
- CVE-2015-8361CRITICALCVSS 9.1EG 9.12016-02-08
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vecto…
- CVE-2015-8512MEDIUMCVSS 4.6EG 4.62016-01-09
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.
- CVE-2015-8523HIGHCVSS 7.5EG 7.52016-04-05
The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) via crafted packets to a TCP port.
- CVE-2015-8550HIGHCVSS 8.2EG 8.22016-04-14
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnera…
- CVE-2015-8627MEDIUMCVSS 5.3EG 5.32017-03-23
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize IP addresses containing zero-padded octets, which might allow remote attackers to bypass intended access restrictions …
- CVE-2015-8679MEDIUMCVSS 5.5EG 5.52016-04-07
The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and…
- CVE-2015-8680HIGHCVSS 7.8EG 7.82016-04-07
The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S …
- CVE-2015-8681HIGHCVSS 7.8EG 7.82016-04-07
The ovisp driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S sma…
- CVE-2015-8697MEDIUMCVSS 5.5EG 5.52017-06-27
stalin 0.11-5 allows local users to write to arbitrary files.
- CVE-2015-8801LOWCVSS 2.9EG 2.92016-06-30
Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a n…
- CVE-2015-8832HIGHCVSS 8.8EG 8.82017-02-09
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute ar…
- CVE-2015-8838MEDIUMCVSS 5.9EG 5.92016-05-16
ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a r…
- CVE-2015-8845MEDIUMCVSS 5.5EG 5.52016-04-27
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a…
- CVE-2015-8973HIGHCVSS 8.3EG 8.32017-01-31
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.
- CVE-2015-8987MEDIUMCVSS 5.3EG 5.32017-03-14
Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attackers to make a McAfee Agent talk with another, possibly rogue, ePO server via McAfee Agent m…
- CVE-2015-9006HIGHCVSS 7.8EG 7.82017-06-06
In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially exist.
- CVE-2015-9021MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
- CVE-2015-9024MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
- CVE-2015-9029HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.
- CVE-2015-9040CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.
- CVE-2015-9047CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup.
- CVE-2015-9064CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request before NAS security has been activated.
- CVE-2015-9140HIGHCVSS 7.5EG 7.52018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 20…
- CVE-2015-9152CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile IPQ4019, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 800…
- CVE-2015-9209CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410…
- CVE-2015-9236MEDIUMCVSS 5.3EG 5.32018-05-31
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the connection has CORS…
- CVE-2015-9243MEDIUMCVSS 5.9EG 5.92018-05-29
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security…
- CVE-2015-9245CRITICALCVSS 9.8EG 9.82017-10-31
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →