Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2019-06-17 CVE-2019-4174 Improper Privilege Management vulnerability in IBM Cognos Controller
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-06-12 CVE-2019-1007 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.8
2019-06-11 CVE-2019-12794 Improper Privilege Management vulnerability in Misp 2.4.108
An issue was discovered in MISP 2.4.108.
network
high complexity
misp CWE-269
6.6
2019-06-07 CVE-2019-12775 Improper Privilege Management vulnerability in Enttec products
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482.
network
low complexity
enttec CWE-269
8.8
2019-06-06 CVE-2019-4218 Improper Privilege Management vulnerability in IBM Security Information Queue 1.0.0/1.0.1/1.0.2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-269
3.3
2019-06-06 CVE-2019-4048 Improper Privilege Management vulnerability in IBM products
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine.
low complexity
ibm CWE-269
2.1
2019-06-03 CVE-2019-12176 Improper Privilege Management vulnerability in HTC Viveport
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service.
local
low complexity
htc CWE-269
7.8
2019-06-03 CVE-2019-10144 Improper Privilege Management vulnerability in Redhat RKT
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`.
local
low complexity
redhat CWE-269
7.7
2019-05-29 CVE-2019-11896 Improper Privilege Management vulnerability in Bosch Smart Home Controller Firmware 9.8.905
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions.
high complexity
bosch CWE-269
7.1
2019-05-29 CVE-2019-11893 Improper Privilege Management vulnerability in Bosch Smart Home Controller Firmware
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions.
low complexity
bosch CWE-269
8.0