A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response di
An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensit
An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light str
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieva
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software o
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default pa
Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authentica
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate w
SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow a
Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile()
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege E
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authentica
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated
Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to
Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may all
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may
Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticate
Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.22). The affected application is instal
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddU
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information vi
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and F
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-clu
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overal
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an H
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affec
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with k
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attack
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linu
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 1
EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora i
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions start
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When
In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started