Vulnerabilities > Permission Issues

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2016-10846 Permission Issues vulnerability in Cpanel
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
network
low complexity
cpanel CWE-275
8.1
2019-07-03 CVE-2017-9327 Permission Issues vulnerability in Cloudera Manager 5.10.1/5.11.0/5.9.2
Secret data of processes managed by CM is not secured by file permissions.
network
low complexity
cloudera CWE-275
6.5
2019-05-23 CVE-2017-17060 Permission Issues vulnerability in Open-Xchange Appsuite
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
network
low complexity
open-xchange CWE-275
critical
9.8
2018-11-26 CVE-2017-1418 Permission Issues vulnerability in IBM Integration BUS and Websphere Message Broker
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files.
local
low complexity
ibm CWE-275
5.5
2018-09-11 CVE-2016-7066 Permission Issues vulnerability in Redhat Jboss Enterprise Application Platform
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
local
low complexity
redhat CWE-275
7.8
2018-08-28 CVE-2014-6047 Permission Issues vulnerability in PHPmyfaq
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
network
low complexity
phpmyfaq CWE-275
5.3
2018-08-06 CVE-2017-1396 Permission Issues vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
low complexity
ibm CWE-275
8.1
2018-07-27 CVE-2017-2590 Permission Issues vulnerability in multiple products
A vulnerability was found in ipa before 4.4.
network
low complexity
freeipa redhat CWE-275
8.1
2018-06-11 CVE-2016-9061 Permission Issues vulnerability in Mozilla Firefox
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only.
network
low complexity
mozilla CWE-275
7.5
2018-06-11 CVE-2016-5299 Permission Issues vulnerability in Mozilla Firefox
A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only.
network
low complexity
mozilla CWE-275
7.5