Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2018-03-23 CVE-2018-1000141 Improper Privilege Management vulnerability in I-Librarian I Librarian
I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining unauthorized access (read, write and delete) to project discussions.
network
low complexity
i-librarian CWE-269
critical
9.1
2018-03-22 CVE-2017-0935 Improper Privilege Management vulnerability in UI Edgeos 1.9.1/1.9.1.1
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed.
network
low complexity
ui CWE-269
8.8
2018-03-22 CVE-2017-0934 Improper Privilege Management vulnerability in Ubnt Edgeos
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed.
network
low complexity
ubnt CWE-269
8.8
2018-03-22 CVE-2017-0932 Improper Privilege Management vulnerability in Ubnt Edgeos
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the input of the Feature functionality.
network
low complexity
ubnt CWE-269
8.8
2018-03-20 CVE-2017-5736 Improper Privilege Management vulnerability in Intel Software Guard Extensions Platform Software Component
An elevation of privilege in Intel Software Guard Extensions Platform Software Component before 1.9.105.42329 allows a local attacker to execute arbitrary code as administrator.
local
low complexity
intel CWE-269
8.8
2018-03-20 CVE-2017-8187 Improper Privilege Management vulnerability in Huawei Fusionsphere Openstack Firmware V100R006C00Spc102(Nfv)
Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability.
network
low complexity
huawei CWE-269
7.2
2018-03-20 CVE-2018-4844 Improper Privilege Management vulnerability in Siemens Simatic Wincc OA UI
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10).
low complexity
siemens CWE-269
6.7
2018-03-16 CVE-2018-1000133 Improper Privilege Management vulnerability in Secluded Trident 1.4.6
Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unprivileged user could gain system administrator permissions within the web portal..
network
high complexity
secluded CWE-269
7.5
2018-03-08 CVE-2018-1182 Improper Privilege Management vulnerability in multiple products
An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management & Governance (RSA IMG) versions 6.9.0, 6.9.1, all patch levels (hardware appliance and software bundle deployments only).
local
low complexity
emc rsa CWE-269
7.8
2018-03-08 CVE-2017-6152 Improper Privilege Management vulnerability in F5 Big-Iq Centralized Management 5.1.0/5.2.0
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.
local
low complexity
f5 CWE-269
6.7