VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 126 of 255
  • CVE-2025-67507HigDec 10, 2025
    risk 0.46cvss 8.1epss 0.00

    Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue…

  • CVE-2025-55340HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

  • CVE-2024-12310HigJul 23, 2025
    risk 0.46cvss —epss 0.00

    A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to…

  • CVE-2025-7699HigJul 16, 2025
    risk 0.46cvss —epss 0.00

    An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the server file system into their own EZSync folder. The vulnerability is due to a lack of authorization checks on the file parameter…

  • CVE-2025-49146HigJun 11, 2025
    risk 0.46cvss 8.2epss 0.00

    pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that…

  • CVE-2025-48909HigJun 6, 2025
    risk 0.46cvss 7.1epss 0.00

    Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-45106HigDec 3, 2024
    risk 0.46cvss 8.1epss 0.01

    Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. The default value of…

  • CVE-2024-51997HigNov 8, 2024
    risk 0.46cvss 8.1epss 0.00

    Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by AS, could be manipulated by MITM attacker, but the verifier (CoCo Verification Demander like KBS) could still…

  • CVE-2024-9946HigNov 6, 2024
    risk 0.46cvss 8.1epss 0.01

    The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by the social login…

  • CVE-2024-10020HigNov 6, 2024
    risk 0.46cvss 8.1epss 0.01

    The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated…

  • CVE-2024-10097HigNov 5, 2024
    risk 0.46cvss 8.1epss 0.01

    The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for…

  • CVE-2024-8642HigSep 11, 2024
    risk 0.46cvss 8.1epss 0.00

    In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The…

  • CVE-2024-39830HigJul 3, 2024
    risk 0.46cvss 8.1epss 0.00

    Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote…

  • CVE-2024-34103HigJun 13, 2024
    risk 0.46cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the…

  • CVE-2024-22257HigMar 18, 2024
    risk 0.46cvss 8.2epss 0.01

    In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the…

  • CVE-2024-21390HigMar 12, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft Authenticator Elevation of Privilege Vulnerability

  • CVE-2022-41737HigFeb 17, 2024
    risk 0.46cvss 7.1epss 0.00

    IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.

  • CVE-2023-33070HigDec 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Transient DOS in Automotive OS due to improper authentication to the secure IO calls.

  • CVE-2023-4677HigNov 23, 2023
    risk 0.46cvss 7.0epss 0.00

    Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an…

  • CVE-2023-39215HigSep 12, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.