CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,295 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 53 of 126
- CVE-2024-1887MEDIUMCVSS 4.3EG 4.32024-02-29
Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export.
- CVE-2024-1888MEDIUMCVSS 4.3EG 4.32024-02-29
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was alread…
- CVE-2024-1898MEDIUMCVSS 4.3EG 4.32024-03-05
Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator.
- CVE-2024-1942MEDIUMCVSS 4.3EG 4.32024-02-29
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts…
- CVE-2024-20036MEDIUMCVSS 4.4EG 4.42024-03-04
In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; I…
- CVE-2024-20065MEDIUMCVSS 4.0EG 4.02024-06-03
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pa…
- CVE-2024-2019HIGHCVSS 7.5EG 7.52024-06-04
The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a default capability requirement on the 'dbte_render' function in all versions up to, and inclu…
- CVE-2024-20261MEDIUMCVSS 5.8EG 5.82024-05-22
A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encr…
- CVE-2024-20263MEDIUMCVSS 5.8EG 5.82024-01-26
A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to byp…
- CVE-2024-20279MEDIUMCVSS 4.3EG 4.32024-08-28
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality …
- CVE-2024-20283MEDIUMCVSS 4.3EG 4.32024-04-03
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An a…
- CVE-2024-20291MEDIUMCVSS 5.8EG 5.82024-02-29
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should b…
- CVE-2024-20302MEDIUMCVSS 5.4EG 5.42024-04-03
A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to i…
- CVE-2024-20315MEDIUMCVSS 5.8EG 5.82024-03-13
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to im…
- CVE-2024-20319MEDIUMCVSS 4.3EG 4.32024-03-13
A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of…
- CVE-2024-20322MEDIUMCVSS 5.8EG 5.82024-03-13
A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due…
- CVE-2024-20325MEDIUMCVSS 5.1EG 5.12024-02-21
A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerab…
- CVE-2024-20343MEDIUMCVSS 5.5EG 5.52024-09-11
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device.…
- CVE-2024-20373MEDIUMCVSS 5.3EG 5.32024-11-15
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP p…
- CVE-2024-20397MEDIUMCVSS 5.2EG 5.22024-12-04
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signat…
- CVE-2024-20465MEDIUMCVSS 5.8EG 5.82024-09-25
A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. Thi…
- CVE-2024-20657HIGHCVSS 7.0EG 7.02024-01-09
Windows Group Policy Elevation of Privilege Vulnerability
- CVE-2024-20675MEDIUMCVSS 6.3EG 6.32024-01-11
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- CVE-2024-20695MEDIUMCVSS 5.7EG 5.72024-02-13
Skype for Business Information Disclosure Vulnerability
- CVE-2024-20767CRITICALCVSS 7.4EG 9.0⚠ KEV2024-03-18
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. E…
- CVE-2024-20911LOWCVSS 2.6EG 2.62024-02-17
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to …
- CVE-2024-20912LOWCVSS 2.7EG 2.72024-01-16
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to co…
- CVE-2024-20916HIGHCVSS 8.3EG 8.32024-01-16
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows high privileged …
- CVE-2024-20918HIGHCVSS 7.4EG 7.42024-01-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21…
- CVE-2024-20926MEDIUMCVSS 5.9EG 5.92024-01-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21; Oracle G…
- CVE-2024-20927HIGHCVSS 8.6EG 8.62024-02-17
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with …
- CVE-2024-20929MEDIUMCVSS 6.5EG 6.52024-02-17
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacke…
- CVE-2024-20931HIGHCVSS 7.5EG 8.32024-02-17
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with …
- CVE-2024-20932HIGHCVSS 7.5EG 7.52024-01-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.…
- CVE-2024-20936MEDIUMCVSS 6.1EG 6.12024-01-16
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with n…
- CVE-2024-20938MEDIUMCVSS 6.1EG 6.12024-01-16
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…
- CVE-2024-20948MEDIUMCVSS 6.1EG 6.12024-01-16
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with …
- CVE-2024-20951MEDIUMCVSS 6.1EG 6.12024-02-17
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated atta…
- CVE-2024-20952HIGHCVSS 7.4EG 7.42024-01-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 2…
- CVE-2024-20969MEDIUMCVSS 5.5EG 5.52024-01-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with netw…
- CVE-2024-20992MEDIUMCVSS 4.4EG 4.42024-04-16
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content integration). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker wi…
- CVE-2024-21067HIGHCVSS 8.8EG 8.82024-04-16
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows low privileged at…
- CVE-2024-21071CRITICALCVSS 9.1EG 9.12024-04-16
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker wi…
- CVE-2024-21074HIGHCVSS 7.5EG 7.52024-04-16
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with netwo…
- CVE-2024-21076HIGHCVSS 7.5EG 7.52024-04-16
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Offer LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network…
- CVE-2024-21084MEDIUMCVSS 5.8EG 5.82024-04-16
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Service Gateway). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with n…
- CVE-2024-21091MEDIUMCVSS 6.5EG 6.52024-04-16
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged…
- CVE-2024-21103HIGHCVSS 7.8EG 7.82024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21107MEDIUMCVSS 6.7EG 6.72024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the inf…
- CVE-2024-21110HIGHCVSS 7.3EG 7.32024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →