Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2023-05-12 CVE-2023-28522 Incorrect Permission Assignment for Critical Resource vulnerability in IBM API Connect 10.0.0.0/10.0.1.0/10.0.1.1
IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to.
network
low complexity
ibm CWE-732
8.8
2023-05-11 CVE-2023-31445 Incorrect Permission Assignment for Critical Resource vulnerability in Cassianetworks Access Controller 2.0.1
Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.
network
low complexity
cassianetworks CWE-732
5.3
2023-05-10 CVE-2022-38103 Incorrect Permission Assignment for Critical Resource vulnerability in Intel NUC Software Studio Service
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access
local
low complexity
intel CWE-732
7.8
2023-05-10 CVE-2022-41658 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Vtune Profiler
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2023-05-10 CVE-2022-41699 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Quickassist Technology 1.6
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2023-05-10 CVE-2022-41771 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Quickassist Technology 1.6
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-732
5.5
2023-05-10 CVE-2022-46656 Incorrect Permission Assignment for Critical Resource vulnerability in Intel NUC PRO Software Suite
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2023-05-08 CVE-2023-2478 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2.
network
low complexity
gitlab CWE-732
6.5
2023-05-05 CVE-2021-40331 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Ranger
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin.
network
low complexity
apache CWE-732
8.1
2023-05-05 CVE-2023-28068 Incorrect Permission Assignment for Critical Resource vulnerability in Dell Command | Monitor 10.9
Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability.
local
low complexity
dell CWE-732
7.8