CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,277 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 35 of 126
- CVE-2022-39871HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.
- CVE-2022-39875MEDIUMCVSS 5.1EG 5.12022-10-07
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
- CVE-2022-39877MEDIUMCVSS 4.0EG 5.32022-10-07
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
- CVE-2022-39878MEDIUMCVSS 4.0EG 5.52022-10-07
Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit intent broadcast.
- CVE-2022-39884MEDIUMCVSS 4.3EG 4.32022-11-09
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
- CVE-2022-39887MEDIUMCVSS 4.3EG 4.32022-11-09
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.
- CVE-2022-39889MEDIUMCVSS 4.0EG 4.02022-11-09
Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information.
- CVE-2022-39894MEDIUMCVSS 4.0EG 4.02022-12-08
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
- CVE-2022-39895MEDIUMCVSS 4.0EG 4.02022-12-08
Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.
- CVE-2022-39896MEDIUMCVSS 4.0EG 4.02022-12-08
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
- CVE-2022-39898MEDIUMCVSS 4.0EG 4.02022-12-08
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
- CVE-2022-39900MEDIUMCVSS 4.6EG 4.62022-12-08
Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.
- CVE-2022-39906LOWCVSS 2.3EG 3.32022-12-08
Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.
- CVE-2022-39910MEDIUMCVSS 3.9EG 4.22022-12-08
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.
- CVE-2022-39915MEDIUMCVSS 3.3EG 5.52022-12-08
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information v…
- CVE-2022-39946HIGHCVSS 7.6EG 7.62023-06-13
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on …
- CVE-2022-40036MEDIUMCVSS 6.5EG 6.52023-01-26
An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component.
- CVE-2022-40207HIGHCVSS 8.2EG 8.22023-05-10
Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-40216MEDIUMCVSS 4.3EG 6.52022-11-18
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
- CVE-2022-40529HIGHCVSS 7.1EG 7.12023-06-06
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
- CVE-2022-40539HIGHCVSS 8.4EG 8.42023-03-10
Memory corruption in Automotive Android OS due to improper validation of array index.
- CVE-2022-40633MEDIUMCVSS 4.6EG 4.62023-03-02
A malicious actor can clone access cards used to open control cabinets secured with Rittal CMC III locks.
- CVE-2022-40798HIGHCVSS 7.5EG 7.52022-10-19
OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover.
- CVE-2022-4087MEDIUMCVSS 2.6EG 4.32022-11-21
A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to informatio…
- CVE-2022-40964HIGHCVSS 7.9EG 7.92023-08-11
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-40972MEDIUMCVSS 6.7EG 6.72023-05-10
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41135MEDIUMCVSS 6.5EG 6.52022-11-18
Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
- CVE-2022-41155CRITICALCVSS 5.3EG 9.82022-11-19
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
- CVE-2022-41235MEDIUMCVSS 5.3EG 6.52022-09-21
Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
- CVE-2022-41261MEDIUMCVSS 6.0EG 6.02022-12-12
SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access oth…
- CVE-2022-41324MEDIUMCVSS 6.5EG 6.52024-06-20
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.
- CVE-2022-41621LOWCVSS 3.3EG 3.32023-05-10
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-41652CRITICALCVSS 6.5EG 9.82022-11-18
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
- CVE-2022-41654MEDIUMCVSS 4.3EG 4.32022-12-22
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger …
- CVE-2022-41659LOWCVSS 1.9EG 1.92023-11-14
Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
- CVE-2022-41677MEDIUMCVSS 5.3EG 5.32023-12-18
An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possi…
- CVE-2022-41689HIGHCVSS 7.3EG 7.32023-11-14
Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41690HIGHCVSS 7.1EG 7.12023-05-10
Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41769MEDIUMCVSS 4.8EG 4.82023-05-10
Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41784HIGHCVSS 8.8EG 8.82023-05-10
Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access
- CVE-2022-41970LOWCVSS 2.6EG 2.62022-12-01
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be d…
- CVE-2022-42126MEDIUMCVSS 4.3EG 4.32022-11-15
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view …
- CVE-2022-4229CRITICALCVSS 7.3EG 9.82022-11-30
A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability affects unknown code of the file /bsms_ci/index.php. The manipulation leads to improper access controls. The attack can…
- CVE-2022-4232CRITICALCVSS 4.7EG 9.82022-11-30
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the …
- CVE-2022-42327HIGHCVSS 7.1EG 7.12022-11-01
x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode. Access to this shared p…
- CVE-2022-42465HIGHCVSS 7.2EG 7.22023-05-10
Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-42707HIGHCVSS 7.5EG 7.52022-11-06
In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions.
- CVE-2022-42717HIGHCVSS 7.8EG 7.82022-10-11
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverag…
- CVE-2022-4272CRITICALCVSS 6.3EG 9.82022-12-03
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestr…
- CVE-2022-4273CRITICALCVSS 7.3EG 9.82022-12-03
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Han…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →