CWE-287
4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,461)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address. |
The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network sessio...Show more |
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter. |
1Redhat 3Jboss Enterprise Brms Platform Jboss Enterprise Portal PlatformJboss Enterprise Soa PlatformApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 3.3 LOW· v2 JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the...Show more |
1Sinapsitech 4Esolar Duo Photovoltaic System Monitor Esolar Light Photovoltaic System MonitorEsolar Photovoltaic System Monitor+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative...Show more |
1Ibm 1Websphere Datapower Xc10 Appliance Apr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (pro...Show more |
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper...Show more |
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it...Show more |
1Emc 1Rsa Data Protection Manager Appliance Apr 29, 2026 Nov 16, 2012 N/A· v4 N/A· v3 6.9 MEDIUM· v2 EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access res...Show more |
MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, v...Show more |
1Ibm 2Tivoli Federated Identity Manager Tivoli Federated Identity Manager Business GatewayApr 29, 2026 Nov 8, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all...Show more |
1Cisco 115500 Series Adaptive Security Appliance Adaptive Security Appliance SoftwareCatalyst 6500+8 moreApr 29, 2026 Oct 29, 2012 N/A· v4 N/A· v3 7.1 HIGH· v2 The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 befo...Show more |
1Eduserv 1Openathens Service Provider Apr 29, 2026 Oct 9, 2012 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack." |
1Josso 1Java Open Single Sign On Project Home Apr 29, 2026 Oct 9, 2012 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack." |
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418. |
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." |
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesti...Show more |
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary...Show more |
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack. |