Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2018-01-10 CVE-2016-9722 Improper Access Control vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
high complexity
ibm CWE-284
4.2
2017-12-29 CVE-2015-8008 Improper Access Control vulnerability in multiple products
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.
network
low complexity
mediawiki fedoraproject CWE-284
7.5
2017-12-29 CVE-2015-3302 Improper Access Control vulnerability in Thecartpress Ecommerce Shopping Cart
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
network
low complexity
thecartpress CWE-284
7.5
2017-10-31 CVE-2015-9245 Improper Access Control vulnerability in Progress Openedge
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.
network
low complexity
progress CWE-284
critical
9.8
2017-10-30 CVE-2014-3624 Improper Access Control vulnerability in Apache Traffic Server 5.1.0
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
network
low complexity
apache CWE-284
critical
9.8
2017-10-30 CVE-2013-4246 Improper Access Control vulnerability in Apache Subversion 1.8.0/1.8.1
libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.
network
low complexity
apache CWE-284
8.8
2017-10-23 CVE-2010-2232 Improper Access Control vulnerability in Apache Derby
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
network
low complexity
apache CWE-284
7.5
2017-10-19 CVE-2012-4380 Improper Access Control vulnerability in Mediawiki
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.
network
low complexity
mediawiki CWE-284
7.5
2017-10-19 CVE-2012-4379 Improper Access Control vulnerability in Mediawiki
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via an embedded API response in an IFRAME element.
network
low complexity
mediawiki CWE-284
6.5
2017-10-18 CVE-2016-5714 Improper Access Control vulnerability in Puppet Agent and Puppet Enterprise
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."
network
low complexity
puppet CWE-284
7.2