The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and
The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.
The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save buil
PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authenticat
A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUS
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information
IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the H
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the serv
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups'
A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any auth
Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents w
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group wri
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group wri
Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group w
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticate
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" s
IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentic
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix]
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. Th
Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the rece
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `tru
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.1
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStru
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalati
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures d
SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI.
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA V
Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users gr
BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job S
Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification o
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started