VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 153 of 241
  • CVE-2019-18286MedDec 12, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive information. This vulnerability is independent from CVE-2019-18287. Please note that an…

  • CVE-2019-14870MedDec 10, 2019
    risk 0.35cvss 5.4epss 0.03

    All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or…

  • CVE-2019-19507MedDec 2, 2019
    risk 0.35cvss 5.3epss 0.01

    In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite…

  • CVE-2019-14856MedNov 26, 2019
    risk 0.35cvss 6.5epss 0.02

    ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

  • CVE-2019-15987MedNov 26, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA…

  • CVE-2019-3654MedNov 22, 2019
    risk 0.35cvss 5.3epss 0.01

    Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key on the client which…

  • CVE-2019-8108MedNov 5, 2019
    risk 0.35cvss 6.5epss 0.01

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation setting for a storefront that leads to insecure authentication and session…

  • CVE-2019-1980MedNov 5, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The…

  • CVE-2016-10983MedSep 17, 2019
    risk 0.35cvss 6.5epss 0.02

    The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.

  • CVE-2019-13190MedSep 5, 2019
    risk 0.35cvss 5.3epss 0.01

    In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.

  • CVE-2019-3884MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

  • CVE-2019-10966MedJul 10, 2019
    risk 0.35cvss 5.3epss 0.01

    In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.

  • CVE-2019-12845MedJul 3, 2019
    risk 0.35cvss 5.3epss 0.01

    The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.

  • CVE-2019-1842MedJun 5, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to a logic error that may occur when…

  • CVE-2018-0382MedApr 17, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists…

  • CVE-2019-0282MedApr 10, 2019
    risk 0.35cvss 5.3epss 0.01

    Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Java package and Java object names which…

  • CVE-2019-1759MedMar 28, 2019
    risk 0.35cvss 5.3epss 0.04

    A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability…

  • CVE-2017-2659MedMar 21, 2019
    risk 0.35cvss 5.3epss 0.02

    It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

  • CVE-2019-1666MedFeb 21, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by…

  • CVE-2018-19000MedFeb 5, 2019
    risk 0.35cvss 5.3epss 0.09

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.