Vulnerabilities > Privilege Defined With Unsafe Actions

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-43746 Privilege Defined With Unsafe Actions vulnerability in F5 products
When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
network
low complexity
f5 CWE-267
8.7
2023-06-01 CVE-2023-22647 Privilege Defined With Unsafe Actions vulnerability in Suse Rancher
An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being preserved.
low complexity
suse CWE-267
8.0
2023-05-30 CVE-2023-2983 Privilege Defined With Unsafe Actions vulnerability in Pimcore
Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.
network
low complexity
pimcore CWE-267
8.8
2023-03-14 CVE-2023-27895 Privilege Defined With Unsafe Actions vulnerability in SAP Authenticator 1.3.0
SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device.
network
low complexity
sap CWE-267
6.5
2021-07-15 CVE-2021-32739 Privilege Defined With Unsafe Actions vulnerability in multiple products
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting.
network
low complexity
icinga debian CWE-267
6.5
2019-11-29 CVE-2019-14865 Privilege Defined With Unsafe Actions vulnerability in GNU Grub2
A flaw was found in the grub2-set-bootflag utility of grub2.
local
low complexity
gnu CWE-267
5.5