SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScr
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as exe
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions sett
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source r
In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege es
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Mast
Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Pr
Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allow
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege admi
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation
If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to exec
Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by ad
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe
There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerabili
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file
'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe
'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL
Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writab
Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade proce
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local a
A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer
Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing
In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic err
In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be th
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel
In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a perm
The Automox Agent before 40 on Windows incorrectly sets permissions on key files.
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. Th
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly a
File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensit
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started