← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
5Security Access Manager For Mobile Appliance
Security Access Manager For Mobile SoftwareSecurity Access Manager For Web 8.0 Firmware+2 more
May 6, 2026
Jun 21, 2014
N/A· v4
N/A· v3
8.0 HIGH· v2
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allo...Show more
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.Show less
1Hp
1Executive Scorecard
May 6, 2026
Jun 19, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.
1Cisco
1Nx Os
May 6, 2026
Jun 14, 2014
N/A· v4
N/A· v3
4.8 MEDIUM· v2
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packe...Show more
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.Show less
1Dotclear
1Dotclear
May 6, 2026
Jun 11, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.
1Typo3
1Typo3
May 6, 2026
Jun 3, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass...Show more
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.Show less
1Typo3
1Typo3
May 6, 2026
Jun 3, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors.
1Lucas Clemente Vella
1Libpam Pgsql
May 6, 2026
Jun 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password.
1Redhat
1Openstack
May 6, 2026
Jun 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote...Show more
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote attackers to gain access by connecting to Qpid.Show less
1Citrix
1Vdi In A Box
May 6, 2026
May 30, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet.
1Bitrix
1Bitrix E Store Module
May 6, 2026
May 30, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via...Show more
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.Show less
1Cisco
1Unified Communications Domain Manager
May 6, 2026
May 29, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain s...Show more
The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive user and group information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum77005.Show less
1Google Authenticator Login Project
1Ga Login
May 6, 2026
May 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).
1Apache
1Hbase
May 6, 2026
May 29, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecif...Show more
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.Show less
1Axway
2Email Firewall
Secure Messenger
May 6, 2026
May 27, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumera...Show more
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.Show less
1Moodle
1Moodle
May 6, 2026
May 27, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to...Show more
login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.Show less
1Ibm
1Sametime
May 6, 2026
May 26, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
1Ibm
1Sametime
May 6, 2026
May 26, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain s...Show more
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive information by leveraging the presence of HTTP requests.Show less
2Apache
Citrix
2Cloudplatform
Cloudstack
May 6, 2026
May 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the sour...Show more
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.Show less
1Hanon
5Faceid
Faceid F710 FirmwareFaceid F810 Firmware+2 more
May 6, 2026
May 22, 2014
N/A· v4
N/A· v3
8.3 HIGH· v2
Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data via API commands.
1Opentext
1Exceed Ondemand
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authen...Show more
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.Show less