CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,291 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 39 of 126
- CVE-2023-2183MEDIUMCVSS 4.1EG 4.12023-06-06
Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a…
- CVE-2023-21832HIGHCVSS 8.8EG 8.82023-01-18
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged atta…
- CVE-2023-21846HIGHCVSS 8.8EG 8.82023-01-18
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged atta…
- CVE-2023-21849HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with networ…
- CVE-2023-21850HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2023-21851HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with…
- CVE-2023-21852HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network …
- CVE-2023-21853HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker wi…
- CVE-2023-21854HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with netw…
- CVE-2023-21855HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Pocket Outlook Sync(PocketPC)). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticate…
- CVE-2023-21857HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated atta…
- CVE-2023-21860MEDIUMCVSS 6.3EG 6.32023-01-18
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected are 7.4.38 and prior, 7.5.28 and prior, 7.6.24 and prior and 8.0.31 and prior. Difficult to exploi…
- CVE-2023-21893HIGHCVSS 7.5EG 7.52023-01-18
Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS…
- CVE-2023-21894HIGHCVSS 7.3EG 7.32023-01-18
Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vul…
- CVE-2023-21901HIGHCVSS 7.4EG 7.42024-01-16
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.…
- CVE-2023-21905MEDIUMCVSS 6.1EG 6.12023-04-18
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability all…
- CVE-2023-21922MEDIUMCVSS 6.8EG 6.82023-04-18
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allow…
- CVE-2023-21923HIGHCVSS 8.3EG 8.32023-04-18
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows …
- CVE-2023-21968LOWCVSS 3.7EG 3.72023-04-18
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enter…
- CVE-2023-21969MEDIUMCVSS 6.7EG 6.72023-04-18
Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SQL …
- CVE-2023-21980HIGHCVSS 7.1EG 7.12023-04-18
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker wit…
- CVE-2023-21985HIGHCVSS 7.7EG 7.72023-04-18
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure whe…
- CVE-2023-22014HIGHCVSS 8.4EG 8.42023-07-18
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with logon …
- CVE-2023-2202MEDIUMCVSS 6.5EG 6.52023-04-21
Improper Access Control in GitHub repository francoisjacquet/rosariosis prior to 10.9.3.
- CVE-2023-22102HIGHCVSS 8.3EG 8.32023-10-17
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via m…
- CVE-2023-22232HIGHCVSS 5.3EG 8.82023-02-17
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrit…
- CVE-2023-22250MEDIUMCVSS 5.3EG 5.32023-03-27
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the …
- CVE-2023-22285HIGHCVSS 7.5EG 7.52023-11-14
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
- CVE-2023-22293HIGHCVSS 8.2EG 8.22024-02-14
Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-22311HIGHCVSS 6.7EG 7.82024-02-14
Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-22312HIGHCVSS 7.2EG 7.22023-05-10
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-22335HIGHCVSS 7.5EG 7.52023-03-06
Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to bypass access restriction and download an arbitrary file of the directory where the produc…
- CVE-2023-22339HIGHCVSS 7.5EG 7.52023-01-20
Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate including the private key of the product.
- CVE-2023-22448MEDIUMCVSS 5.9EG 5.92023-11-14
Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access.
- CVE-2023-22473LOWCVSS 2.1EG 2.12023-01-09
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physic…
- CVE-2023-22487HIGHCVSS 7.7EG 7.72023-01-11
Flarum is a forum software for building communities. Using the mentions feature provided by the flarum/mentions extension, users can mention any post ID on the forum with the special `@"<username>"#p<id>` syntax. The following behavior nev…
- CVE-2023-22600CRITICALCVSS 10.0EG 10.02023-01-12
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-284: Improper Access Control. They allow unauthenticated devices to subscribe to MQTT …
- CVE-2023-22618HIGHCVSS 8.1EG 8.12023-10-04
If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, Wa…
- CVE-2023-22805MEDIUMCVSS 6.5EG 6.52023-02-15
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from the device.
- CVE-2023-22807CRITICALCVSS 9.8EG 9.82023-02-15
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protoco…
- CVE-2023-22848MEDIUMCVSS 5.5EG 5.52024-02-14
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-22903CRITICALCVSS 9.8EG 9.82023-01-10
api/views/user.py in LibrePhotos before e19e539 has incorrect access control.
- CVE-2023-22920CRITICALCVSS 9.8EG 9.82023-02-21
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to acc…
- CVE-2023-22960HIGHCVSS 7.5EG 7.52023-01-23
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
- CVE-2023-23445HIGHCVSS 7.5EG 7.52023-05-15
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpr…
- CVE-2023-23446HIGHCVSS 7.5EG 7.52023-05-15
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the…
- CVE-2023-23508MEDIUMCVSS 5.5EG 5.52023-02-27
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to bypass Privacy preferences.
- CVE-2023-23573MEDIUMCVSS 4.4EG 4.42023-05-10
Improper access control in the Intel(R) Unite(R) android application before Release 17 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-23575MEDIUMCVSS 4.3EG 4.32023-04-11
Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass access restriction and access Network Maintenance page, which may result in obtaining the network information of the p…
- CVE-2023-23615MEDIUMCVSS 5.3EG 5.32023-02-03
Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions o…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →