Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead t
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affe
The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access t
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due
Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote l
An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authent
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the aff
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an p
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The curren
Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to del
Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they
Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is poss
An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Netw
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remot
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuratio
Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privil
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows att
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user w
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated
A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the
An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root
Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unp
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Auth
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an imprope
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Au
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could cha
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even whe
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possibl
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorize
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC applica
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privilege
Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private fil
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action withou
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android
Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerabil
Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untr
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authori
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started