Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2021-08-03 CVE-2021-33333 Incorrect Default Permissions vulnerability in Liferay DXP 7.0
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
network
low complexity
liferay CWE-276
6.5
2021-08-03 CVE-2021-33334 Incorrect Default Permissions vulnerability in Liferay DXP 7.0
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration.
network
low complexity
liferay CWE-276
4.0
2021-08-03 CVE-2021-33324 Incorrect Default Permissions vulnerability in Liferay DXP and Liferay Portal
The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.
network
low complexity
liferay CWE-276
4.0
2021-08-03 CVE-2021-33327 Incorrect Default Permissions vulnerability in Liferay DXP and Liferay Portal
The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.
network
low complexity
liferay CWE-276
4.0
2021-07-29 CVE-2020-5353 Incorrect Default Permissions vulnerability in Dell EMC Isilon Onefs and EMC Powerscale Onefs
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory.
network
low complexity
dell CWE-276
critical
9.0
2021-07-28 CVE-2020-26180 Incorrect Default Permissions vulnerability in Dell EMC Isilon Onefs and EMC Powerscale Onefs
Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account.
network
low complexity
dell CWE-276
6.5
2021-07-19 CVE-2020-29503 Incorrect Default Permissions vulnerability in Dell EMC Powerstore
Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file permission Vulnerability.
local
low complexity
dell CWE-276
2.1
2021-07-15 CVE-2020-25593 Incorrect Default Permissions vulnerability in Acronis True Image
Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.
local
low complexity
acronis CWE-276
7.2
2021-07-14 CVE-2021-0441 Incorrect Default Permissions vulnerability in Google Android 11.0
In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI.
local
google CWE-276
4.4
2021-07-14 CVE-2021-0486 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0
In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass.
local
low complexity
google CWE-276
4.6