Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability.
Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability.
An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 befor
A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitr
A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbit
An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privil
"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. Th
An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3.
An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastr
Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.
Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixl
A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTF
A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This i
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to r
Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consu
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficie
The setup program for the affected product configures its files and folders with full access, which may allow unauthoriz
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit
SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a f
Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive inf
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privilege
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impac
Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could
A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more acc
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for Open
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can c
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Su
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthoriz
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to bypa
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 1
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An a
IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to imp
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ven
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be a
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able t
An access issue was addressed with additional sandbox restrictions. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadO
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may b
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS V
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started