← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linux
1Linux Kernel
Apr 29, 2026
Oct 3, 2012
N/A· v4
N/A· v3
1.9 LOW· v2
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demons...Show more
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.Show less
1Nextbbs
1Nextbbs
Apr 29, 2026
Oct 1, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.
1Condor Project
1Condor
Apr 29, 2026
Sep 28, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to imp...Show more
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.Show less
1Emc
2Rsa Authentication Agent
Rsa Authentication Client
Apr 29, 2026
Sep 25, 2012
N/A· v4
N/A· v3
8.5 HIGH· v2
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to...Show more
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.Show less
1Oracle
2Database Server
Primavera P6 Enterprise Project Portfolio Management
Apr 29, 2026
Sep 21, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information...Show more
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."Show less
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
1.9 LOW· v2
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authen...Show more
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that performs purchase transactions.Show less
1Apple
1Mac Os X
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors.
1Nomachine
1Nx Web Companion
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) Red...Show more
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.Show less
1Imgpals
1Img Pals Photo Host
Apr 29, 2026
Sep 15, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
1Gentoo
1Webmin
Apr 29, 2026
Sep 11, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.
1Owncloud
1Owncloud Server
Apr 29, 2026
Sep 5, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value.
1Packetfence
1Packetfence
Apr 29, 2026
Aug 31, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the...Show more
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the User-Name RADIUS attribute.Show less
1Emc
2Cloud Tiering Appliance
Cloud Tiering Appliance Virtual Edition
Apr 29, 2026
Aug 29, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access by sending a crafted...Show more
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access by sending a crafted file during the authentication phase.Show less
1Apache
1Qpid
Apr 29, 2026
Aug 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
1Condor Project
1Condor
Apr 29, 2026
Aug 25, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
1Websense
1Websense Web Security
Apr 29, 2026
Aug 23, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles fie...Show more
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorer_wse/favorites.exe.Show less
1Mcafee
1Smartfilter Administration
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attack...Show more
McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file.Show less
1Mcafee
2Email And Web Security
Email Gateway
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication and obtain an admin session ID via unspeci...Show more
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication and obtain an admin session ID via unspecified vectors.Show less
1Mcafee
2Email And Web Security
Email Gateway
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Cons...Show more
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session cookie and then modifying the response to a login attempt, related to a "Logout Failure" issue.Show less
1Mcafee
1Firewall Reporter
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obtain access, and disable anti-virus functionality, via an HTTP request.