VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,083)

page 167 of 255
  • CVE-2021-3424MedJun 1, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.

  • CVE-2021-32646MedMay 28, 2021
    risk 0.35cvss 5.3epss 0.01

    Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and text channels. A vulnerability has been discovered allowing discord users to get the ``manage channel`` permissions in a private VC they have joined. This…

  • CVE-2021-20278MedMay 28, 2021
    risk 0.35cvss 6.5epss 0.01

    An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by the underlying cluster. When OpenID `implicit flow` is used…

  • CVE-2021-32541MedMay 28, 2021
    risk 0.35cvss 5.3epss 0.02

    The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attackers can send a large number of valid usernames, and force those logged-in account to log out, causing the user to be unable to…

  • CVE-2018-16496MedMay 26, 2021
    risk 0.35cvss 5.3epss 0.01

    In Versa Director, the un-authentication request found.

  • CVE-2020-26139MedMay 11, 2021
    risk 0.35cvss 5.3epss 0.06

    An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against…

  • CVE-2021-30158MedApr 6, 2021
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been…

  • CVE-2021-21335MedMar 8, 2021
    risk 0.35cvss 5.3epss 0.02

    In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in…

  • CVE-2021-3332MedMar 1, 2021
    risk 0.35cvss 5.3epss 0.02

    WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.

  • CVE-2020-26834MedDec 9, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical to the truncated username for…

  • CVE-2020-28896MedNov 23, 2020
    risk 0.35cvss 5.3epss 0.02

    Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in…

  • CVE-2020-4771MedNov 23, 2020
    risk 0.35cvss 5.3epss 0.02

    IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream,…

  • CVE-2020-8267MedNov 5, 2020
    risk 0.35cvss 5.3epss 0.01

    A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated messages without a valid token.This vulnerability was…

  • CVE-2020-28002MedNov 2, 2020
    risk 0.35cvss 5.3epss 0.01

    In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit…

  • CVE-2020-25867MedOct 7, 2020
    risk 0.35cvss 5.3epss 0.03

    SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.

  • CVE-2020-3197MedJul 16, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection…

  • CVE-2019-20412MedJun 29, 2020
    risk 0.35cvss 5.3epss 0.02

    The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue…

  • CVE-2017-18919MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.

  • CVE-2016-11072MedJun 19, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.

  • CVE-2019-20875MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.