Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2020-04-16 CVE-2020-4347 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Infosphere Information Server 11.3/11.5/11.7
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permissions for files used by WebSphere Application Server Network Deployment.
network
low complexity
ibm CWE-732
7.3
2020-04-15 CVE-2020-0557 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Proset/Wireless Wifi
Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2020-04-15 CVE-2020-10699 Incorrect Permission Assignment for Critical Resource vulnerability in Targetcli-Fb Project Targetcli-Fb 2.1.50/2.1.51
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable.
local
low complexity
targetcli-fb-project CWE-732
7.8
2020-04-15 CVE-2020-10513 Incorrect Permission Assignment for Critical Resource vulnerability in Icatchinc DVR Interface
The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate arbitrary file.
network
low complexity
icatchinc CWE-732
6.5
2020-04-13 CVE-2020-10642 Incorrect Permission Assignment for Critical Resource vulnerability in Rockwellautomation Rslinx Classic 4.1.00/4.11.00
In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registry key, which could lead to the execution of malicious code using system privileges when opening RSLinx Classic.
local
low complexity
rockwellautomation CWE-732
7.8
2020-04-09 CVE-2020-10551 Incorrect Permission Assignment for Critical Resource vulnerability in Tencent Qqbrowser
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.
local
low complexity
tencent CWE-732
7.8
2020-04-08 CVE-2018-21081 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x) software.
network
low complexity
google CWE-732
critical
9.1
2020-04-08 CVE-2020-4289 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Security Information Queue
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.
network
low complexity
ibm CWE-732
5.3
2020-04-08 CVE-2019-4603 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Rational Quality Manager 6.0.2/6.0.6/6.0.6.1
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user.
network
low complexity
ibm CWE-732
4.3
2020-04-02 CVE-2020-11107 Incorrect Permission Assignment for Critical Resource vulnerability in Apachefriends Xampp
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.
network
low complexity
apachefriends CWE-732
8.8