← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
271921 Integrated Services Router
1941 Integrated Services Router1941w Integrated Services Router+24 more
Apr 29, 2026
May 8, 2013
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to cause a denial of service (module reload) via a series of malformed packets...Show more
The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to cause a denial of service (module reload) via a series of malformed packets, aka Bug ID CSCub92025.Show less
1Strongswan
1Strongswan
Apr 29, 2026
May 2, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
1Cisco
6Unified Computing System 6120xp Fabric Interconnect
Unified Computing System 6140xp Fabric InterconnectUnified Computing System 6248up Fabric Interconnect+3 more
Apr 29, 2026
Apr 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), a...Show more
Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746.Show less
1Novell
1Imanager
Apr 29, 2026
Apr 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
1Ibm
1Websphere Application Server
Apr 29, 2026
Apr 24, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access res...Show more
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.Show less
1Apache
1Activemq
Apr 29, 2026
Apr 21, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
1Redhat
1Jboss Enterprise Portal Platform
Apr 29, 2026
Apr 12, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or...Show more
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or alter the access controls for portlets.Show less
1Openstack
1Keystone
Apr 29, 2026
Apr 12, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dep...Show more
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.Show less
1Cisco
1Firewall Services Module Software
Apr 29, 2026
Apr 11, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1(5.1) allows remote attackers to cause a denial of service (device relo...Show more
The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCtg02624.Show less
1Cisco
2Adaptive Security Appliance
Adaptive Security Appliance Software
Apr 29, 2026
Apr 11, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3...Show more
The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3), 8.5 and 8.6 before 8.6(1.10), 8.7 before 8.7(1.4), 9.0 before 9.0(1.1), and 9.1 before 9.1(1.2) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCud16590.Show less
1Ithemes
1Backupbuddy
Apr 29, 2026
Apr 2, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.
1Ithemes
1Backupbuddy
Apr 29, 2026
Apr 2, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite...Show more
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.Show less
1Novell
1Zenworks Configuration Management
Apr 29, 2026
Mar 29, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory travers...Show more
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.Show less
1Emc
1Smarts Network Configuration Manager
Apr 29, 2026
Mar 28, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
EMC Smarts Network Configuration Manager (NCM) before 9.2 does not require authentication for all Java RMI method calls, which allows remote attackers to execute arbitrary code via unspecified vectors.
1Google Authenticator Login Project
1Ga Login
Apr 29, 2026
Mar 27, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Auth...Show more
The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.Show less
1Ibm
1Lotus Domino
Apr 29, 2026
Mar 27, 2013
N/A· v4
N/A· v3
8.5 HIGH· v2
The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration details, aka SPR KLYH8TNNDN.
2Canonical
Openstack
2Folsom
Ubuntu Linux
Apr 29, 2026
Mar 22, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI to...Show more
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.Show less
1Apache
1Qpid
Apr 29, 2026
Mar 14, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authenticati...Show more
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.Show less
1Apache
1Cxf
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request...Show more
Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.Show less
1Apache
1Cxf
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP...Show more
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.Show less