Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2019-12-03 CVE-2019-4465 Improper Privilege Management vulnerability in IBM Cloud PAK System 2.3/2.3.0.1
IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-12-02 CVE-2012-4480 Improper Privilege Management vulnerability in multiple products
mom creates world-writable pid files in /var/run
local
low complexity
ovirt fedoraproject CWE-269
7.8
2019-12-02 CVE-2019-19014 Improper Privilege Management vulnerability in Titanhq Webtitan
An issue was discovered in TitanHQ WebTitan before 5.18.
local
low complexity
titanhq CWE-269
7.8
2019-11-27 CVE-2019-6668 Improper Privilege Management vulnerability in F5 Big-Ip Access Policy Manager
The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5 may allow unprivileged users to access files owned by root.
local
low complexity
f5 CWE-269
5.5
2019-11-27 CVE-2013-2625 Improper Privilege Management vulnerability in multiple products
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8.
network
low complexity
otrs debian opensuse CWE-269
6.5
2019-11-26 CVE-2019-7319 Improper Privilege Management vulnerability in Cloudera CDH 6.0.0/6.0.1/6.1.0
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0.
network
low complexity
cloudera CWE-269
8.3
2019-11-26 CVE-2017-7399 Improper Privilege Management vulnerability in Cloudera Manager
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
network
low complexity
cloudera CWE-269
8.8
2019-11-26 CVE-2015-7831 Improper Privilege Management vulnerability in Cloudera CDH
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
network
low complexity
cloudera CWE-269
8.8
2019-11-25 CVE-2012-6639 Improper Privilege Management vulnerability in multiple products
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
network
low complexity
canonical debian suse CWE-269
8.8
2019-11-25 CVE-2019-13705 Improper Privilege Management vulnerability in multiple products
Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
network
low complexity
google opensuse CWE-269
4.3