CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,293 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 41 of 126
- CVE-2023-26408HIGHCVSS 7.8EG 7.82023-04-12
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation…
- CVE-2023-26460MEDIUMCVSS 5.3EG 5.32023-03-14
Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity
- CVE-2023-26471CRITICALCVSS 9.9EG 9.92023-03-02
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into acc…
- CVE-2023-26473MEDIUMCVSS 6.5EG 6.52023-03-02
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.…
- CVE-2023-26474CRITICALCVSS 9.9EG 9.92023-03-02
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There …
- CVE-2023-26585MEDIUMCVSS 5.0EG 5.02024-02-14
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-26596LOWCVSS 2.5EG 2.52024-02-14
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-2670MEDIUMCVSS 6.3EG 6.32023-05-12
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/?page=user/manage_user. The manipulation leads to improper acces…
- CVE-2023-2674HIGHCVSS 4.3EG 8.82023-05-12
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- CVE-2023-26770CRITICALCVSS 9.8EG 9.82024-10-04
TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.
- CVE-2023-27088HIGHCVSS 8.8EG 8.82023-03-08
feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to…
- CVE-2023-27268MEDIUMCVSS 5.3EG 5.32023-03-14
SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to acces…
- CVE-2023-27301MEDIUMCVSS 4.2EG 4.22024-02-14
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-27303LOWCVSS 3.8EG 3.82024-02-14
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2023-27350CRITICALCVSS 9.8EG 9.8⚠ KEV2023-04-20
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompl…
- CVE-2023-27391MEDIUMCVSS 6.7EG 6.72023-08-11
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-27509MEDIUMCVSS 6.6EG 6.62023-08-11
Improper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user to potentially enable escalation of privileges via local access.
- CVE-2023-27517HIGHCVSS 6.6EG 7.82024-02-14
Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00.0483 may allow an athenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-27578CRITICALCVSS 9.1EG 9.12023-03-20
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as th…
- CVE-2023-27875HIGHCVSS 7.5EG 7.52023-03-16
IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.
- CVE-2023-27879MEDIUMCVSS 6.8EG 6.82023-11-14
Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2023-28051HIGHCVSS 7.8EG 7.82023-04-07
Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.
- CVE-2023-28066HIGHCVSS 7.3EG 7.32023-06-01
Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability in order to elevate privileges on the sys…
- CVE-2023-28068HIGHCVSS 7.3EG 7.32023-05-05
Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authenticated malicious user can potentially exploit this vulnerability leading to privilege escalation by writing to a protected…
- CVE-2023-28070MEDIUMCVSS 6.7EG 6.72023-05-03
Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A local malicious user could potentially exploit this vulnerability during installation or update process leading to priv…
- CVE-2023-28197LOWCVSS 3.3EG 3.32024-01-10
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.
- CVE-2023-28246HIGHCVSS 7.8EG 7.82023-04-11
Windows Registry Elevation of Privilege Vulnerability
- CVE-2023-28300HIGHCVSS 7.5EG 7.52023-04-11
Azure Service Connector Security Feature Bypass Vulnerability
- CVE-2023-28312MEDIUMCVSS 6.5EG 6.52023-04-11
Azure Machine Learning Information Disclosure Vulnerability
- CVE-2023-28372MEDIUMCVSS 6.5EG 6.52023-10-02
A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock.
- CVE-2023-28396MEDIUMCVSS 6.1EG 6.12024-02-14
Improper access control in firmware for some Intel(R) Thunderbol(TM) Controllers versions before 41 may allow a privileged user to enable denial of service via local access.
- CVE-2023-28397HIGHCVSS 7.8EG 7.82023-11-14
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access.
- CVE-2023-28443MEDIUMCVSS 4.2EG 4.22023-03-24
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permiss…
- CVE-2023-2845HIGHCVSS 8.1EG 8.82023-05-23
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
- CVE-2023-28531CRITICALCVSS 9.8EG 9.82023-03-17
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
- CVE-2023-28600MEDIUMCVSS 5.2EG 5.22023-06-13
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.
- CVE-2023-28603HIGHCVSS 7.7EG 7.72023-06-13
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
- CVE-2023-2861MEDIUMCVSS 6.0EG 6.02023-12-06
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creati…
- CVE-2023-28645MEDIUMCVSS 5.7EG 5.72023-03-31
Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich document…
- CVE-2023-28714HIGHCVSS 8.2EG 8.22023-08-11
Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-28715MEDIUMCVSS 5.0EG 5.52024-02-14
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-28808CRITICALCVSS 9.1EG 9.82023-04-11
Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
- CVE-2023-28809HIGHCVSS 7.5EG 7.52023-06-15
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the s…
- CVE-2023-28810MEDIUMCVSS 4.3EG 4.32023-06-15
Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the…
- CVE-2023-28844MEDIUMCVSS 5.7EG 5.72023-03-31
Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been address…
- CVE-2023-28845LOWCVSS 3.5EG 3.52023-03-31
Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information ab…
- CVE-2023-28877HIGHCVSS 7.5EG 7.52023-03-31
The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration data. (apps-graphql@3.x is unaffected by this issue.)
- CVE-2023-28907MEDIUMCVSS 6.7EG 6.72025-06-28
There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was origina…
- CVE-2023-2901MEDIUMCVSS 4.3EG 4.32023-05-25
A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /SystemManage/User/GetGridJson?_search=false&nd=16808554797…
- CVE-2023-2902MEDIUMCVSS 4.3EG 4.32023-05-25
A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=false&nd=168181352078…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →