← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Kies Air
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.
1Emc
1It Operations Intelligence
Apr 29, 2026
Nov 27, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network sessio...Show more
The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session.Show less
1Awcm Cms
1Ar Web Content Manager
Apr 29, 2026
Nov 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.
1Redhat
3Jboss Enterprise Brms Platform
Jboss Enterprise Portal PlatformJboss Enterprise Soa Platform
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows...Show more
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.Show less
1Redhat
4Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+1 more
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the...Show more
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.Show less
1Sinapsitech
4Esolar Duo Photovoltaic System Monitor
Esolar Light Photovoltaic System MonitorEsolar Photovoltaic System Monitor+1 more
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative...Show more
These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.Show less
1Ibm
1Websphere Datapower Xc10 Appliance
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (pro...Show more
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (process exit) via unknown vectors.Show less
1Apache
1Tomcat
Oct 30, 2025
Nov 17, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper...Show more
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.Show less
1Apache
1Tomcat
Apr 29, 2026
Nov 17, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it...Show more
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.Show less
1Emc
1Rsa Data Protection Manager Appliance
Apr 29, 2026
Nov 16, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access res...Show more
EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access restrictions via a brute-force attack.Show less
1Mosp
1Kintai Kanri
Apr 29, 2026
Nov 8, 2012
N/A· v4
N/A· v3
5.5 MEDIUM· v2
MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, v...Show more
MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, via unspecified vectors.Show less
1Ibm
2Tivoli Federated Identity Manager
Tivoli Federated Identity Manager Business Gateway
Apr 29, 2026
Nov 8, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all...Show more
The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to bypass intended J2EE security constraints, and obtain sensitive information related to (1) federation metadata or (2) a web plugin configuration template, via a crafted request.Show less
1Cisco
115500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareCatalyst 6500+8 more
Apr 29, 2026
Oct 29, 2012
N/A· v4
N/A· v3
7.1 HIGH· v2
The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 befo...Show more
The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.30) and 8.3 before 8.3(2.34) allows remote attackers to cause a denial of service (device reload) via a crafted authentication response, aka Bug ID CSCtz04566.Show less
1Eduserv
1Openathens Service Provider
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
1Josso
1Java Open Single Sign On Project Home
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
1Apache
1Axis2
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability than CVE-2012-4418.
1Apache
1Axis2
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
1Openstack
1Keystone
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesti...Show more
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.Show less
1Openstack
1Keystone
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary...Show more
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.Show less
1Ibm
1Lotus Notes Traveler
Apr 29, 2026
Oct 8, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.