CWE-287
4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,464)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows attackers to (1) delete or (2) upload snapshots. |
Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization of the loading of a plug-in, which makes it easier for remote attackers...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Feb 27, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the remote LBM Hub node, which allows remote a...Show more |
1Bigantsoft 1Bigant Im Message Server Apr 29, 2026 Feb 24, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors. |
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows...Show more |
The WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza, when SSL is not enabled, allows remote attackers to discover credentials by sniffing the network during the authentication process. |
1Ibm 2San Volume Controller Software Storwize V7000Apr 29, 2026 Feb 19, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain superuser access via IP packets. |
1Vmware 6Esx EsxiVcenter Server+3 moreApr 29, 2026 Feb 15, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and V...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5...Show more |
1Ibm 2Infosphere Information Server Infosphere Information Server Information Services FrameworkApr 29, 2026 Jan 31, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly determine authorization, which allows remote authenticated users to gain privileges via unspecified...Show more |
1Rockwellautomation 171756 Enbt 1756 Eweb1768 Enbt+14 moreJun 3, 2026 Jan 24, 2013 N/A· v4 4.8 MEDIUM· v3 9.3 HIGH· v2 The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to...Show more |
1Rockwellautomation 171756 Enbt 1756 Eweb1768 Enbt+14 moreJun 3, 2026 Jan 24, 2013 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitatio...Show more |
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL...Show more |
5Canonical MozillaOpensuse+2 more14Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+11 moreApr 29, 2026 Jan 13, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers...Show more |
Dl Download Ticket Service 0.3 through 0.9 allows remote attackers to login as an arbitrary user by supplying an authorization header. |
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January...Show more |
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which all...Show more |
The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support. |
1Microfocus 1Privileged User Manager Apr 29, 2026 Dec 24, 2012 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the...Show more |
2Foscam Wansview2H.264 Hi3510/11/12 Ip Camera H.264 Hi3510/11/12 Ip CameraApr 29, 2026 Dec 21, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or read the admin password, via a direct request to an unspecified URL. |