In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions
A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_au
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize opt
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a u
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and Ai
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at
Possible unauthorized memory access in the hypervisor. Incorrect configuration provides access to subsystem page tables.
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could pote
In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could po
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level admi
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zuli
An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The is
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing B
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical e
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password wi
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started