A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and mo
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and S
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote at
A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting acces
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xd
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows at
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms.
WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does
A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software runnin
Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers
The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attacke
In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small C
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and S
A vulnerability in open build service allows remote attackers to gain access to source files even though source access i
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the
IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which ma
A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE L
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can c
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that ha
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arb
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, wh
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixe
If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be af
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allow
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requir
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated,
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attac
The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, w
Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion re
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using
Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access n
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having acces
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the ra
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" a
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authentica
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined an
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started