CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2022-46257 MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.3
CVE-2022-44310 HIGH
ecdh < 0.2.0 - Exposure of Resource to Wrong Sphere via Invalid Public Key
CVSS 7.5
CVE-2022-39952 CRITICAL
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVSS 9.8
CVE-2022-34387 MEDIUM
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Privilege Escalation via Insecure Temporary File
CVSS 6.4
CVE-2022-34364 MEDIUM
BSAFE SSL-J <6.5, 7.0 - Info Disclosure
CVSS 4.4
CVE-2022-4903 MEDIUM
CodenameOne < 7.0.71 - Use of Implicit Intent for Sensitive Communication
CVSS 5.0
CVE-2022-34452 LOW
Dell PowerPath Management Appliance 3.0-3.3 - Authenticated Sensitive Information Disclosure via Log Files
CVSS 2.7
CVE-2022-46756 HIGH
Dell VxRail < 7.0.410 - Container Escape and OS Command Execution
CVSS 8.2
CVE-2022-22732 LOW
EcoStruxure Power Commission < 2.22 - Exposure of Resource to Wrong Sphere via Fetch Request
CVSS 3.9
CVE-2022-26329 LOW
NetIQ Identity Manager <4.8.5 - Info Disclosure
CVSS 1.8
CVE-2022-45438 MEDIUM
Apache Superset <=1.5.2 and 2.0.0 - Unauthenticated Exposure of Dashboard Metadata via REST API
CVSS 5.3
CVE-2022-24913 MEDIUM
java-merge-sort < 1.1.0 - Insecure Temporary File via StdTempFileProvider
CVSS 5.5
CVE-2022-45935 MEDIUM
Apache James < 3.7.2 - Unprotected User Data Exposure via Temporary Files
CVSS 5.5
CVE-2022-0337 MEDIUM
Google Chrome <97.0.4692.71 - Info Disclosure
CVSS 6.5
CVE-2022-48198 CRITICAL
ntpd_driver < 1.3.0 and 2.x < 2.2.0 - Unauthenticated Exposure of Resource to Wrong Sphere via time_ref_topic Parameter
CVSS 9.8
CVE-2022-4817 LOW
centic9 jgit-cookbook - Insecure Temp File
CVSS 3.1
CVE-2022-45895 MEDIUM
Planet eStream < 6.72.10.07 - Sensitive Information Exposure via ON Cookie and WhoAmI Endpoint
CVSS 6.5
CVE-2022-38474 MEDIUM
Firefox < 104.0 for Android - Unauthenticated Audio Recording Without Notification
CVSS 4.3
CVE-2022-31596 MEDIUM
SAP BusinessObjects <430 - Info Disclosure
CVSS 6.0
CVE-2022-38599 MEDIUM
Teleport v3.2.2 v3.5.6-rc6 v3.6.3-b2 - Information Leak via /user/get-role-list
CVSS 6.5
CVE-2022-32221 CRITICAL
curl - Exposure of Sensitive Information via Reused Handle Logic
CVSS 9.8
CVE-2022-41971 MEDIUM
Nextcloud Talk 12.0.0-12.2.7 - Unauthorized Video Stream Access After Removal
CVSS 4.8
CVE-2022-43901 MEDIUM
IBM WebSphere Automation <1.4.3 - Info Disclosure
CVSS 5.7
CVE-2022-1911 MEDIUM
M-Files Server <22.6.11534.1, <22.6.11505.0 - Info Disclosure
CVSS 5.3
CVE-2022-21126 HIGH
htsjdk < 3.0.1 - Insecure Temporary Directory Creation in IOUtil.createTempDir()
CVSS 7.3
Details
Vulnerabilities 719