CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

483 vulnerabilities with CWE-552
CVE-2019-25709 CRITICAL
CF Image Hosting Script 1.6.5 Unauthorized Database Access
CVSS 9.8
CVE-2019-25239 HIGH
V-SOL GPON/EPON OLT Platform 2.03 - Info Disclosure
CVSS 7.5
CVE-2019-3897 MEDIUM
Red Hat Certification <6-7 - Info Disclosure
CVSS 5.3
CVE-2019-7306 MEDIUM
byobu - Information Disclosure via Apport Hook
CVSS 4.3
CVE-2019-7305 MEDIUM
eXtplorer < 2.1.0 - Information Exposure via World-Accessible System Directories
CVSS 5.8
CVE-2019-20593 MEDIUM
Samsung Mobile <O - Info Disclosure
CVSS 5.3
CVE-2019-20529 HIGH
Frappe 11-12 - Unauthenticated Sensitive Data Exposure via Prepared Report File Storage
CVSS 7.5
CVE-2019-13941 HIGH
OZW Web Server < V10.00 - Info Disclosure
CVSS 7.5
CVE-2019-19843 CRITICAL
Ruckus Wireless Unleashed <200.7.10.102.64 - Info Disclosure
CVSS 9.8
CVE-2019-19018 LOW
TitanHQ WebTitan <5.18 - Info Disclosure
CVSS 2.7
CVE-2019-17221 HIGH
PhantomJS < 2.1.1 - Arbitrary File Read via XMLHttpRequest for file:// URI
CVSS 7.5
CVE-2019-4398 LOW
IBM Cloud Orchestrator <2.5.0.9, <2.4.0.5 - Info Disclosure
CVSS 3.3
CVE-2019-17112 MEDIUM
Zoho ManageEngine DataSecurity Plus <5.0.1 5012 - Info Disclosure
CVSS 4.3
CVE-2019-0381 MEDIUM
SAP SQL Anywhere <17.0 - Info Disclosure
CVSS 5.5
CVE-2019-17130 MEDIUM
vBulletin <= 5.5.4 - Information Exposure via External URL Handling
CVSS 6.5
CVE-2019-14273 MEDIUM
SilverStripe assets <4.0 - Info Disclosure
CVSS 5.3
CVE-2019-13140 MEDIUM
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 - Unauthenticated 3DES Key Extraction via JUCI ACL Misconfiguration
CVSS 6.5
CVE-2019-3622 HIGH
McAfee DLPe <11.3.0 - Privilege Escalation
CVSS 8.2
CVE-2019-10930 HIGH
SIPROTEC 5 and DIGSI 5 Engineering Software < V7.90 - Unauthenticated Arbitrary File Access via TCP Port 443
CVSS 7.5
CVE-2019-13404 HIGH
Python < 2.7.16 - Unprotected User Data Exposure via Default Installation Directory
CVSS 7.8
CVE-2019-3569 HIGH
HHVM < 3.30.5 and 4.0-4.8 - Unintended FastCGI Interface Binding
CVSS 7.5
CVE-2019-12375 MEDIUM
Ivanti LANDESK Management Suite <10.0.1.168 - RCE/Info Disclosure
CVSS 6.3
CVE-2019-3811 MEDIUM
sssd < 2.1 - Unintended Home Directory Path Disclosure
CVSS 5.2
CVE-2018-25164 HIGH
EverSync 0.5 - Unauthenticated Arbitrary File Download via Files Directory
CVSS 7.5
CVE-2018-25145 MEDIUM
Microhard Systems IPn4G 1.1.0 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 483