Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-08-21 CVE-2019-11847 Improper Privilege Management vulnerability in Sierrawireless Aleos
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9.
local
low complexity
sierrawireless CWE-269
7.2
2020-08-21 CVE-2020-10290 Improper Privilege Management vulnerability in Sintef URX
Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video.
local
low complexity
sintef CWE-269
7.2
2020-08-21 CVE-2020-7710 Improper Privilege Management vulnerability in Safe-Eval Project Safe-Eval
This affects all versions of package safe-eval.
network
low complexity
safe-eval-project CWE-269
7.5
2020-08-21 CVE-2020-7310 Improper Privilege Management vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via manipulating symbolic links to redirect a McAfee file operations to an unintended file.
local
high complexity
mcafee CWE-269
6.9
2020-08-20 CVE-2020-15862 Improper Privilege Management vulnerability in multiple products
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
local
low complexity
net-snmp canonical netapp CWE-269
7.8
2020-08-19 CVE-2020-9724 Improper Privilege Management vulnerability in Adobe Lightroom 9.2.0.10
Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability.
network
adobe CWE-269
6.8
2020-08-18 CVE-2020-7019 Improper Privilege Management vulnerability in Elastic Elasticsearch
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security.
network
low complexity
elastic CWE-269
6.5
2020-08-18 CVE-2020-7018 Improper Privilege Management vulnerability in Elastic Enterprise Search
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.
network
low complexity
elastic CWE-269
4.0
2020-08-17 CVE-2020-1488 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges.
local
high complexity
microsoft CWE-269
7.0
2020-08-17 CVE-2020-4686 Improper Privilege Management vulnerability in IBM products
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to.
network
low complexity
ibm CWE-269
5.5