Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-08-16 CVE-2020-10728 Improper Privilege Management vulnerability in Automationbroker APB
A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1.
local
low complexity
automationbroker CWE-269
7.8
2022-08-05 CVE-2022-2498 Improper Privilege Management vulnerability in Gitlab
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
network
low complexity
gitlab CWE-269
7.5
2022-08-05 CVE-2022-36833 Improper Privilege Management vulnerability in Samsung Gameoptimizingservice
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.
local
low complexity
samsung CWE-269
7.8
2022-08-01 CVE-2022-34338 Improper Privilege Management vulnerability in IBM Robotic Process Automation
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types.
network
low complexity
ibm CWE-269
6.5
2022-07-22 CVE-2022-20906 Improper Privilege Management vulnerability in Cisco Nexus Dashboard
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-269
6.7
2022-07-22 CVE-2022-20907 Improper Privilege Management vulnerability in Cisco Nexus Dashboard
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-269
6.7
2022-07-19 CVE-2022-26113 Improper Privilege Management vulnerability in Fortinet Forticlient
An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.
local
low complexity
fortinet CWE-269
7.1
2022-07-19 CVE-2022-30526 Improper Privilege Management vulnerability in Zyxel products
A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.09 through 4.72, which could allow a local attacker to execute some OS commands with root privileges in some directories on a vulnerable device.
local
low complexity
zyxel CWE-269
7.8
2022-07-18 CVE-2022-26118 Improper Privilege Management vulnerability in Fortinet Fortianalyzer and Fortimanager
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
local
low complexity
fortinet CWE-269
6.7
2022-07-12 CVE-2022-33708 Improper Privilege Management vulnerability in Samsung Galaxy Store 4.5.32.4/4.5.36.4
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
local
low complexity
samsung CWE-269
7.8