Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-12-21 CVE-2022-38065 Improper Privilege Management vulnerability in Redhat Openstack
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior.
network
low complexity
redhat CWE-269
8.8
2022-12-20 CVE-2022-42046 Improper Privilege Management vulnerability in WFS Heaven Burns RED 2.5.0
wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation
local
low complexity
wfs CWE-269
7.8
2022-12-13 CVE-2022-38124 Improper Privilege Management vulnerability in Secomea products
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
network
low complexity
secomea CWE-269
6.5
2022-12-13 CVE-2022-41268 Improper Privilege Management vulnerability in SAP Business Planning and Consolidation
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used.
network
high complexity
sap CWE-269
7.5
2022-12-12 CVE-2022-4314 Improper Privilege Management vulnerability in Ikus-Soft Rdiffweb
Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
network
low complexity
ikus-soft CWE-269
critical
9.8
2022-12-12 CVE-2022-37929 Improper Privilege Management vulnerability in HPE products
Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
local
low complexity
hpe CWE-269
5.5
2022-12-10 CVE-2022-23485 Improper Privilege Management vulnerability in Sentry
Sentry is an error tracking and performance monitoring platform.
network
high complexity
sentry CWE-269
3.7
2022-12-09 CVE-2022-4264 Improper Privilege Management vulnerability in M-Files
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
network
low complexity
m-files CWE-269
4.3
2022-12-08 CVE-2022-41948 Improper Privilege Management vulnerability in Dhis2 Dhis 2
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization.
network
low complexity
dhis2 CWE-269
7.2
2022-12-06 CVE-2022-42888 Improper Privilege Management vulnerability in Armemberplugin Armember
Unauth.
network
low complexity
armemberplugin CWE-269
8.8