← Back
CWE-287

4,501 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,501)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Onelogin
1Ruby Saml
Nov 21, 2024
Apr 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryp...Show more
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.Show less
1Onelogin
1Pythonsaml
Nov 21, 2024
Apr 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cry...Show more
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.Show less
1Sap
1Netweaver Process Integration
Jun 17, 2026
Apr 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like relea...Show more
Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Java package and Java object names which can be misused by the attacker.Show less
1Ui
1Edgeswitch X
Jun 17, 2026
Apr 10, 2019
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploi...Show more
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings.Show less
1Tibco
1Activematrix Businessworks
Jun 17, 2026
Apr 9, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even whe...Show more
The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is required. This possibility is restricted to circumstances where HTTP "Basic Authentication" policy is used in conjunction with an XML Authentication resource. The BusinessWorks engine might instead use credentials from a prior HTTP request for authorization purposes. Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to and including 6.4.2.Show less
1Thinkadmin
1Thinkadmin
Jun 17, 2026
Apr 8, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change.
1Hanwhasecurity
1Srn 4000 Firmware
Nov 21, 2024
Apr 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges...Show more
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.Show less
1Uniqkey
1Password Manager
Jun 17, 2026
Apr 5, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for us...Show more
Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for usersite.example.com. This could lead to successful phishing campaigns and create a sense of false security.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Apr 4, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an a...Show more
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.Show less
13m
1Detcon Sitewatch Gateway
Nov 21, 2024
Apr 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Detcon Sitewatch Gateway, all versions without cellular, an attacker can edit settings on the device using a specially crafted URL.
13m
1Detcon Sitewatch Gateway
Nov 21, 2024
Apr 2, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authentication.
1Dell
1Emc Networker
Nov 21, 2024
Apr 1, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated re...Show more
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated remote attacker could send arbitrary commands via RPC service to be executed on the host system with the privileges of the nsrexecd service, which runs with administrative privileges.Show less
1Overit
1Geocall
Jun 17, 2026
Apr 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative...Show more
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative functions.Show less
1Grandstream
1Gxv3611ir Hd Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
1Abine
1Blur
Jun 17, 2026
Mar 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right-click operation to access a forgotten dev menu to insert user passwords that otherwise would requir...Show more
Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right-click operation to access a forgotten dev menu to insert user passwords that otherwise would require the user to accept a second-factor request in a mobile app." approach, related to a "Multifactor Auth Bypass, Full Disk Encryption Bypass" issue affecting the Affected Chrome Plugin component.Show less
1Atlassian
1Crowd
Nov 21, 2024
Mar 29, 2019
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can...Show more
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user's session provided they can make their identifier hash collide with another user's session identifier hash.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Mar 28, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the...Show more
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16.1.1 Release, which prevents the ACL from working when applied against the management interface. An attacker could exploit this issue by attempting to access the device via the management interface.Show less
1Cisco
1Ios
Jun 17, 2026
Mar 28, 2019
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to h...Show more
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to how the 802.1x packets are handled in the process path. An attacker could exploit this vulnerability by attempting to connect to the network on an 802.1x configured port. A successful exploit could allow the attacker to intermittently obtain access to the network.Show less
1Eclipse
1Mosquitto
Nov 21, 2024
Mar 27, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed d...Show more
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs, clients can circumvent authentication and get access to the broker by using the malformed username. In particular, a blank line will be treated as a valid empty username. Other security measures are unaffected. Users who have only used the mosquitto_passwd utility to create and modify their password files are unaffected by this vulnerability.Show less
4Canonical
FedoraprojectMod Auth Mellon Project+1 more
10Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Server+7 more
Jun 17, 2026
Mar 26, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), a...Show more
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.Show less