Vulnerabilities > Permission Issues

DATE CVE VULNERABILITY TITLE RISK
2019-08-02 CVE-2017-18422 Permission Issues vulnerability in Cpanel
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
local
low complexity
cpanel CWE-275
3.3
2019-08-02 CVE-2017-18397 Permission Issues vulnerability in Cpanel
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
local
low complexity
cpanel CWE-275
3.3
2019-08-02 CVE-2017-18390 Permission Issues vulnerability in Cpanel
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
local
low complexity
cpanel CWE-275
7.8
2019-08-01 CVE-2016-10818 Permission Issues vulnerability in Cpanel
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
network
low complexity
cpanel CWE-275
6.5
2019-08-01 CVE-2016-10846 Permission Issues vulnerability in Cpanel
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
network
low complexity
cpanel CWE-275
8.1
2019-07-03 CVE-2017-9327 Permission Issues vulnerability in Cloudera Manager 5.10.1/5.11.0/5.9.2
Secret data of processes managed by CM is not secured by file permissions.
network
low complexity
cloudera CWE-275
6.5
2019-05-23 CVE-2017-17060 Permission Issues vulnerability in Open-Xchange Appsuite
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
network
low complexity
open-xchange CWE-275
critical
9.8
2018-11-26 CVE-2017-1418 Permission Issues vulnerability in IBM Integration BUS and Websphere Message Broker
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files.
local
low complexity
ibm CWE-275
5.5
2018-09-11 CVE-2016-7066 Permission Issues vulnerability in Redhat Jboss Enterprise Application Platform
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
local
low complexity
redhat CWE-275
7.8
2018-08-28 CVE-2014-6047 Permission Issues vulnerability in PHPmyfaq
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
network
low complexity
phpmyfaq CWE-275
5.3