CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2023-36043 MEDIUM
Microsoft Open Management Infrastructure - Information Disclosure
CVSS 6.5
CVE-2023-5545 LOW
moodle < 3.9.24 and >= 4.0.0 < 4.3.0-rc2 - Exposure of Sensitive Information via H5P Metadata Author Field
CVSS 3.3
CVE-2023-5542 LOW
moodle < 4.3.0-rc2 - Improper Access Control in Group Membership Visibility
CVSS 3.3
CVE-2023-42551 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42549 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42547 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42546 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-4910 MEDIUM
3scale_api_management - Exposure of Sensitive Information via Browser Cache
CVSS 5.5
CVE-2023-4217 LOW
PT-G503 Series <5.2 - Info Disclosure
CVSS 3.1
CVE-2023-3972 HIGH
insights-client < 3.2.2 - Local Privilege Escalation via Insecure Temporary Directory Permissions
CVSS 7.8
CVE-2023-2622 LOW
Hitachi Energy Modular Advanced Control for HVDC 7.10.0.0-7.17.x - Arbitrary File Read via InspectSetup RPC
CVSS 2.7
CVE-2023-38994 HIGH
univention_corporate_server 5.0-5 - Exposure of LDAP Credentials in Process List
CVSS 7.9
CVE-2023-37911 MEDIUM
XWiki 9.4-14.10.7 - Unauthorized Deleted Document Content Exposure via Diff Feature
CVSS 6.5
CVE-2023-45145 LOW
Redis 2.6.0-6.2.13 - Unauthenticated Unauthorized Connection via Unix Socket Permission Race Condition
CVSS 3.6
CVE-2023-45911 CRITICAL
WIPOTEC GmbH ComScale <4.4.12.723 - Auth Bypass
CVSS 9.8
CVE-2023-45357 MEDIUM
Archer Platform 6.x < 6.13.0.2.2 - Authenticated Sensitive Information Disclosure via Popup Warning Message
CVSS 4.3
CVE-2023-44394 MEDIUM
MantisBT < 2.25.8 - Unauthorized Private Project Name Exposure via Wiki Page ID Enumeration
CVSS 4.3
CVE-2023-35013 LOW
IBM Security Verify Governance 10.0 - Info Disclosure
CVSS 2.3
CVE-2023-42792 MEDIUM
Apache Airflow < 2.7.2 - Authenticated DAG Resource Access Control Bypass
CVSS 6.5
CVE-2023-32275 MEDIUM
SoftEther VPN 4.41-9782-beta and 5.01.9674 - Information Disclosure via CtEnumCa()
CVSS 5.5
CVE-2023-44102 MEDIUM
Huawei EMUI and HarmonyOS - Bluetooth Module Denial of Service
CVSS 5.3
CVE-2023-44101 HIGH
HarmonyOS - Unauthorized Broadcast Notification Access via Bluetooth Module
CVSS 7.5
CVE-2023-36596 HIGH
Product <Version> - Info Disclosure
CVSS 7.5
CVE-2023-36429 MEDIUM
Microsoft Dynamics 365 (On-Premises) - Info Disclosure
CVSS 6.5
CVE-2023-30802 MEDIUM
Sangfor NGAF 8.0.17 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 719