Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-04-19 CVE-2022-0070 Improper Privilege Management vulnerability in Amazon Log4Jhotpatch
Incomplete fix for CVE-2021-3100.
local
low complexity
amazon CWE-269
8.8
2022-04-19 CVE-2022-0071 Improper Privilege Management vulnerability in Hotdog Project Hotdog
Incomplete fix for CVE-2021-3101.
local
low complexity
hotdog-project CWE-269
8.8
2022-04-15 CVE-2022-20739 Improper Privilege Management vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user.
local
low complexity
cisco CWE-269
7.3
2022-04-14 CVE-2020-16238 Improper Privilege Management vulnerability in Bbraun Datamodule Compactplus and Spacecom
A vulnerability in the configuration import mechanism of the B.
local
low complexity
bbraun CWE-269
6.7
2022-04-14 CVE-2022-22187 Improper Privilege Management vulnerability in Juniper Identity Management Service
An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper Identity Management Service (JIMS) allows an unprivileged user to trigger a repair operation.
local
low complexity
juniper CWE-269
7.8
2022-04-13 CVE-2022-1332 Improper Privilege Management vulnerability in Mattermost Server
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.
network
low complexity
mattermost CWE-269
4.3
2022-04-12 CVE-2022-23160 Improper Privilege Management vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability.
network
low complexity
dell CWE-269
4.3
2022-04-12 CVE-2021-39797 Improper Privilege Management vulnerability in Google Android 12.0/12.1
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code.
local
low complexity
google CWE-269
7.8
2022-04-12 CVE-2021-39807 Improper Privilege Management vulnerability in Google Android
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check.
local
low complexity
google CWE-269
7.8
2022-04-12 CVE-2022-24812 Improper Privilege Management vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-269
8.8