VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 168 of 241
  • CVE-2019-6744MedFeb 10, 2020
    risk 0.28cvss 4.3epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this…

  • CVE-2018-20937MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).

  • CVE-2016-10835MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).

  • CVE-2019-5449MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.

  • CVE-2018-12399MedFeb 28, 2019
    risk 0.28cvss 4.3epss 0.01

    When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability…

  • CVE-2019-3820MedFeb 6, 2019
    risk 0.28cvss 4.3epss 0.01

    It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.

  • CVE-2018-17926MedJan 31, 2019
    risk 0.28cvss 4.3epss 0.01

    The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.

  • CVE-2018-2483MedNov 13, 2018
    risk 0.28cvss 4.3epss 0.01

    HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.

  • CVE-2018-1773MedSep 12, 2018
    risk 0.28cvss 4.3epss 0.01

    IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication mechanisms once the initial login is completed. IBM X-Force ID: 148691.

  • CVE-2018-1999045MedAug 23, 2018
    risk 0.28cvss 5.4epss 0.01

    A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.

  • CVE-2016-6549MedJul 13, 2018
    risk 0.28cvss 4.3epss 0.01

    The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute.

  • CVE-2018-0528MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.

  • CVE-2018-0362MedJun 21, 2018
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged…

  • CVE-2017-5189MedMar 2, 2018
    risk 0.28cvss 4.3epss 0.01

    NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

  • CVE-2017-1000110MedOct 5, 2017
    risk 0.28cvss 4.3epss 0.01

    Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. It did not properly check the current user's authentication and…

  • CVE-2017-1002024MedSep 14, 2017
    risk 0.28cvss 4.3epss 0.01

    Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.

  • CVE-2017-12213MedSep 7, 2017
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open. This could allow the…

  • CVE-2016-4863MedMay 22, 2017
    risk 0.28cvss 4.3epss 0.01

    The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmware version 1.00.04 and…

  • CVE-2026-73840MedAug 13, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key,…

  • CVE-2026-73085MedAug 11, 2026
    risk 0.27cvss epss 0.00

    Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoints such as /api/me instead of restricting…