VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 148 of 241
  • CVE-2025-1231MedFeb 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.

  • CVE-2025-0604MedJan 22, 2025
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in…

  • CVE-2024-13309MedJan 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.

  • CVE-2024-10511MedDec 11, 2024
    risk 0.35cvss 5.3epss 0.01

    CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local network repeatedly requests the /accessdenied URL.

  • CVE-2024-11671MedNov 25, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.

  • CVE-2024-7870MedSep 4, 2024
    risk 0.35cvss 6.5epss 0.00

    The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publicly exposed log files. This makes it…

  • CVE-2024-43409MedAug 20, 2024
    risk 0.35cvss 6.5epss 0.00

    Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains…

  • CVE-2024-40794MedJul 29, 2024
    risk 0.35cvss 5.3epss 0.01

    This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.

  • CVE-2024-32868MedApr 26, 2024
    risk 0.35cvss 6.5epss 0.00

    ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there…

  • CVE-2023-5675MedApr 25, 2024
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is…

  • CVE-2023-39196MedFeb 7, 2024
    risk 0.35cvss 5.3epss 0.01

    Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication. The attacker is not allowed to do any modification within the Ozone Storage…

  • CVE-2024-23647MedJan 30, 2024
    risk 0.35cvss 6.5epss 0.01

    Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the…

  • CVE-2023-7079MedDec 29, 2023
    risk 0.35cvss 6.4epss 0.01

    Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also…

  • CVE-2023-6907MedDec 18, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /file-manager/delete.php of the component Deletion Interface. The manipulation of the argument file leads…

  • CVE-2023-42576MedDec 5, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.

  • CVE-2023-6354MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.

  • CVE-2023-6353MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.

  • CVE-2023-6344MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly…

  • CVE-2023-6343MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server,…

  • CVE-2023-6342MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or…