This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is re
Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to acces
Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, includin
Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which ca
Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-S
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting fr
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). S
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). S
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, una
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality ca
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application cons
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito m
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp
A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backpo
Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary
Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e
An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulner
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The s
A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to a
A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrari
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versi
A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unaut
Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. I
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.
Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file withou
Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and
Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to con
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access locati
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this is
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adja
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be explo
Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access
An Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Releas
Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local user
Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive infor
peertube is vulnerable to Improper Access Control
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started