The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enter
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions <
IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper applicat
A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify r
In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installe
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions.
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges vi
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing autho
The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with inc
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page af
Microsoft SharePoint Server Remote Code Execution Vulnerability
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite ar
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMD
In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default
In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent.
Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authent
In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingInt
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions fo
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP
An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 co
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execu
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in t
Windows Container Manager Service Elevation of Privilege Vulnerability
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing
Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are all
The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability i
Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an
Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may a
Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an
Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authentica
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsa
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could al
In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe Pe
WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executa
Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions
In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable Pend
Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,
An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS)
Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perfor
Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissi
Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated use
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started