CWE-529Variant

Exposure of Access Control List Files to an Unauthorized Control Sphere

Incomplete in the CWE catalog · 1 CVE mapped

1
CVEs mapped
7.5
Median CVSS
What it is

The product stores access control list files in a directory or other container that is accessible to actors outside of the intended control sphere.

Recent examples
7.5cvss
CVE-2014-0752

Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere

The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.

HIGHno explanation yet
2%
epss
The record
Technical detail
CWE ID
CWE-529
Abstraction
Variant
Structure
Simple
Status
Incomplete