CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,279 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 36 of 126
- CVE-2022-4276CRITICALCVSS 6.3EG 9.82022-12-03
A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_phot…
- CVE-2022-42811MEDIUMCVSS 5.5EG 5.52022-11-01
An access issue was addressed with additional sandbox restrictions. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to access user-sensitive data.
- CVE-2022-42814MEDIUMCVSS 5.5EG 5.52022-11-01
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.
- CVE-2022-42816MEDIUMCVSS 5.5EG 5.52024-01-10
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system.
- CVE-2022-42853MEDIUMCVSS 5.5EG 5.52022-12-15
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected parts of the file system.
- CVE-2022-42859MEDIUMCVSS 5.5EG 5.52022-12-15
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.
- CVE-2022-42861HIGHCVSS 8.8EG 8.82022-12-15
This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.
- CVE-2022-42862MEDIUMCVSS 5.5EG 5.52022-12-15
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.
- CVE-2022-42865MEDIUMCVSS 5.5EG 5.52022-12-15
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
- CVE-2022-43110CRITICALCVSS 9.8EG 9.82025-08-22
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system in…
- CVE-2022-4331HIGHCVSS 5.7EG 7.32023-03-09
An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferre…
- CVE-2022-43429HIGHCVSS 7.5EG 7.52022-10-19
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins …
- CVE-2022-43494HIGHCVSS 7.5EG 7.52023-01-18
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.
- CVE-2022-43679MEDIUMCVSS 4.2EG 5.32022-11-10
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.
- CVE-2022-43702HIGHCVSS 7.8EG 7.82023-07-27
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
- CVE-2022-43977CRITICALCVSS 9.8EG 9.82023-01-17
An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control.
- CVE-2022-44014MEDIUMCVSS 6.5EG 6.52022-12-25
An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQL tables. This leaks all user passwords and MSSQL hashes via /DS/LM_API/api/SelectionService/GetPagg…
- CVE-2022-44037HIGHCVSS 8.8EG 8.82022-11-29
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin ri…
- CVE-2022-44211HIGHCVSS 7.4EG 7.42022-12-01
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
- CVE-2022-44212MEDIUMCVSS 5.9EG 5.92022-12-01
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
- CVE-2022-44565MEDIUMCVSS 5.3EG 5.32022-12-23
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
- CVE-2022-44622MEDIUMCVSS 2.7EG 5.32022-11-03
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
- CVE-2022-44643HIGHCVSS 5.7EG 8.82022-12-20
A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenant…
- CVE-2022-44932HIGHCVSS 7.5EG 7.52022-12-08
An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.
- CVE-2022-4505HIGHCVSS 8.8EG 8.82022-12-15
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
- CVE-2022-45112HIGHCVSS 7.3EG 7.32023-08-11
Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-45164MEDIUMCVSS 4.3EG 4.32023-01-10
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to cancel (delete) a booking, created by someone else - even if this basic user is not a member of the booking
- CVE-2022-45166MEDIUMCVSS 6.5EG 6.52023-01-10
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of user-controlled parameters that are used to act on the data returned to the user. It allows a basic user to access data u…
- CVE-2022-45320MEDIUMCVSS 6.3EG 6.32024-02-20
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
- CVE-2022-45430LOWCVSS 3.7EG 3.72022-12-27
Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could en…
- CVE-2022-45431HIGHCVSS 7.5EG 7.52022-12-27
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unau…
- CVE-2022-45438MEDIUMCVSS 5.3EG 5.32023-01-16
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset v…
- CVE-2022-45475HIGHCVSS 6.5EG 8.82022-11-25
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.
- CVE-2022-4567HIGHCVSS 8.1EG 8.12022-12-17
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
- CVE-2022-45778CRITICALCVSS 9.8EG 9.82022-12-27
https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of…
- CVE-2022-45929HIGHCVSS 8.8EG 8.82024-06-20
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-pri…
- CVE-2022-45936HIGHCVSS 8.1EG 8.12022-12-13
A vulnerability has been identified in Mendix Email Connector (All versions < V2.0.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read and m…
- CVE-2022-45937HIGHCVSS 8.8EG 8.82022-12-13
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (A…
- CVE-2022-46025CRITICALCVSS 9.1EG 9.12024-01-10
Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page.
- CVE-2022-46279MEDIUMCVSS 5.0EG 5.02023-05-10
Improper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-46331HIGHCVSS 7.5EG 8.12023-01-18
An unauthorized user could possibly delete any file on the system.
- CVE-2022-46354MEDIUMCVSS 5.3EG 5.32022-12-13
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), …
- CVE-2022-46664HIGHCVSS 8.1EG 8.12022-12-13
A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly …
- CVE-2022-46676MEDIUMCVSS 4.9EG 4.92023-02-11
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized.
- CVE-2022-46677MEDIUMCVSS 6.8EG 6.82023-02-11
Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.
- CVE-2022-46678MEDIUMCVSS 4.9EG 4.92023-02-11
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
- CVE-2022-46754HIGHCVSS 8.7EG 8.72023-02-11
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user control…
- CVE-2022-46755MEDIUMCVSS 4.9EG 4.92023-02-11
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
- CVE-2022-4684HIGHCVSS 8.8EG 8.82022-12-23
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2022-4689HIGHCVSS 8.8EG 8.82022-12-23
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →