CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

2,837 vulnerabilities with CWE-269
CVE-2019-15799 HIGH
Zyxel GS1900 Series Firmware < 2.50 - Privilege Escalation via SSH Access
CVSS 8.8
CVE-2019-14590 MEDIUM
Intel(R) Graphics Driver <26.20.100.7209 - Info Disclosure
CVSS 5.5
CVE-2019-15332 LOW
Lava Z61 Firmware - Improper Privilege Management in com.android.lava.powersave
CVSS 3.3
CVE-2019-3651 HIGH
McAfee Advanced Threat Defense < 4.8 - Authenticated Privilege Escalation via atduser Credentials
CVSS 8.8
CVE-2019-2193 HIGH
Android 8.0-10 - Local Privilege Escalation via Partially Provisioned Device Policy Client
CVSS 7.8
CVE-2019-1405 HIGH KEV
Windows UPnP Service - Privilege Escalation via COM Object Creation
CVSS 7.8
CVE-2019-1388 HIGH KEV
Windows Certificate Dialog - Privilege Escalation
CVSS 7.8
CVE-2019-18845 HIGH
Patriot Viper RGB <1.1 - Memory Corruption
CVSS 7.1
CVE-2019-18623 CRITICAL
EnergyCAP <7.5.6 - Privilege Escalation
CVSS 9.8
CVE-2019-18365 MEDIUM
JetBrains TeamCity < 2019.1.4 - Reverse Tabnabbing
CVSS 4.3
CVE-2019-18425 CRITICAL
Xen < 4.12.1 - 32-bit PV Guest Privilege Escalation via Descriptor Table Limit Bypass
CVSS 9.8
CVE-2019-4546 HIGH
IBM Maximo Health-Safety <7.6.1 - Privilege Escalation
CVSS 8.8
CVE-2019-16897 CRITICAL
K7 Antivirus Premium <16.0.0120 - Privilege Escalation
CVSS 9.8
CVE-2019-10716 HIGH
Verodin Director < 3.5.3.1 - Information Disclosure via /integrations.json API
CVSS 7.7
CVE-2019-15901 HIGH
slicer69 doas <6.2 - Privilege Escalation
CVSS 8.8
CVE-2019-17631 CRITICAL
Eclipse OpenJ9 0.15.0-0.16.0 - Unauthenticated Improper Privilege Management
CVSS 9.1
CVE-2019-16519 HIGH
ESET Cyber Security <6.7.900.0 - Command Injection
CVSS 7.8
CVE-2019-9745 HIGH
CloudCTI HIP Integrator Recognition Configuration Tool - Privilege Escalation
CVSS 7.8
CVE-2019-14838 MEDIUM
WildFly Core < 7.2.5.GA - Improper Access Control for Management Users
CVSS 4.9
CVE-2019-15747 HIGH
SITOS six v6.2.1 - Authenticated Privilege Escalation via Insufficient Role Checks
CVSS 8.8
CVE-2019-4112 LOW
IBM WebSphere eXtreme Scale 8.6.0-8.6.1.2 - Unprotected Local File Exposure via Admin Console
CVSS 3.3
CVE-2019-14220 MEDIUM
BlueStacks <4.110, <4.120 - Local File Read
CVSS 6.5
CVE-2019-11280 HIGH
Pivotal Application Service < 2.3.18, 2.4.14, 2.5.10, 2.6.5 - Privilege Escalation via Invitations
CVSS 8.8
CVE-2019-4477 MEDIUM
IBM WebSphere Application Server - Info Disclosure
CVSS 6.5
CVE-2019-1215 HIGH KEV
Microsoft Windows 10 1507 - Improper Privilege Management
CVSS 7.8
Details
Vulnerabilities 2,837
Exploit Likelihood Medium