In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make
Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parame
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original f
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function t
A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions,
The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s priv
The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remot
Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit em
The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general us
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Auth
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physical
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-b
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an at
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization
GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using g
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remot
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated bu
In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume prope
A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in U
An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS softwa
An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr d
A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All ve
A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration i
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an
Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An a
In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. T
A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated,
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could a
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have
Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with
Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version
An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of
A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could all
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of t
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started