A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments
In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new user
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could hav
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) f
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is op
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inve
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user re
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a mis
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 wh
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization chec
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the I
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integr
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infu
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and ea
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensit
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. Th
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthe
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated r
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All ver
GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an a
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and lau
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote a
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote auth
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could all
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level
A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local att
Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current
An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a u
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insec
A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow a
Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulne
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All ver
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configu
A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an au
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to by
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to by
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started