Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2018-02-09 CVE-2018-1368 Improper Privilege Management vulnerability in IBM Security Guardium Database Activity Monitor 9.0/9.1/9.5
IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to.
local
low complexity
ibm CWE-269
4.4
2018-02-05 CVE-2017-15536 Improper Privilege Management vulnerability in Cloudera Data Science Workbench
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0.
network
low complexity
cloudera CWE-269
8.8
2018-01-16 CVE-2018-5706 Improper Privilege Management vulnerability in Octopus Deploy
An issue was discovered in Octopus Deploy before 4.1.9.
network
low complexity
octopus CWE-269
8.8
2018-01-10 CVE-2018-0010 Improper Privilege Management vulnerability in Juniper Junos Space
A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not have SSH access to a device to reuse the URL that was created for another user to perform SSH access.
network
low complexity
juniper CWE-269
6.5
2018-01-09 CVE-2017-1493 Improper Privilege Management vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls.
network
low complexity
ibm CWE-269
5.4
2018-01-04 CVE-2018-0751 Improper Privilege Management vulnerability in Microsoft products
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability".
local
low complexity
microsoft CWE-269
7.1
2018-01-04 CVE-2018-0748 Improper Privilege Management vulnerability in Microsoft products
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way memory addresses are handled, aka "Windows Elevation of Privilege Vulnerability".
local
low complexity
microsoft CWE-269
7.8
2018-01-03 CVE-2018-4862 Improper Privilege Management vulnerability in Octopus Deploy
In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in such a way as to bypass the scoping restrictions, resulting in a potential escalation of privileges.
network
low complexity
octopus CWE-269
8.8
2017-12-27 CVE-2017-9944 Improper Privilege Management vulnerability in Siemens 7KT Pac1200 Data Manager Firmware
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03.
network
low complexity
siemens CWE-269
critical
9.8
2017-12-20 CVE-2017-5254 Improper Privilege Management vulnerability in Cambiumnetworks Epmp 1000 Firmware and Epmp 2000 Firmware
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.
network
low complexity
cambiumnetworks CWE-269
8.8