Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2019-07-11 CVE-2018-19588 Improper Access Control vulnerability in Alarm Adc-V522Ir Firmware 0100B9
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.
network
low complexity
alarm CWE-284
7.2
2019-07-11 CVE-2018-17151 Improper Access Control vulnerability in Intersystems Cache 2017.2.2.865.0/2018.1.2
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
network
low complexity
intersystems CWE-284
5.4
2019-07-11 CVE-2018-11744 Improper Access Control vulnerability in Cloudera Manager
Cloudera Manager through 5.15 has Incorrect Access Control.
network
high complexity
cloudera CWE-284
8.1
2019-07-10 CVE-2018-19576 Improper Access Control vulnerability in Gitlab
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.
network
low complexity
gitlab CWE-284
8.1
2019-07-10 CVE-2018-19577 Improper Access Control vulnerability in Gitlab
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.
network
low complexity
gitlab CWE-284
5.3
2019-07-10 CVE-2018-19496 Improper Access Control vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1.
network
low complexity
gitlab CWE-284
6.5
2019-07-10 CVE-2018-19494 Improper Access Control vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1.
network
low complexity
gitlab CWE-284
4.3
2019-07-09 CVE-2018-14833 Improper Access Control vulnerability in Intuit Lacerte
Intuit Lacerte 2017 has Incorrect Access Control.
network
high complexity
intuit CWE-284
5.9
2019-07-03 CVE-2018-14859 Improper Access Control vulnerability in Odoo 10.0/11.0/9.0
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token.
network
low complexity
odoo CWE-284
8.1
2019-07-03 CVE-2018-14864 Improper Access Control vulnerability in Odoo 10.0/8.0/9.0
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.
network
low complexity
odoo CWE-284
6.5