← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Heinz Mauelshagen
1Lvm2
Apr 29, 2026
Aug 5, 2010
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which...Show more
The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.Show less
1Ibm
1Tivoli Directory Server
Apr 29, 2026
Aug 2, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attem...Show more
The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.Show less
1Likewise
2Likewise Cifs
Likewise Open
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when ru...Show more
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.Show less
1Sweetphp
1Totalcalender
Apr 29, 2026
Jul 12, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.
1Webmobo
1Wbnews
Apr 29, 2026
Jul 12, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1.
1Adaptivedisplays
2Alpha Ethernet Adapter Ii
Alpha Ethernet Adapter Ii Web Manager
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unspecified vulnerability in Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 allows remote attackers to bypass authentication and read or write configuration files via unknown vectors.
1Mahara
1Mahara
Apr 29, 2026
Jul 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, which allows remote a...Show more
Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, which allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.Show less
1Open Ftpd
1Open Ftpd
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.
1Dootzky
1Oblog
Apr 29, 2026
Jun 25, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Jun 17, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to gain privileges via unspecified vectors.
1Symantec
2Appstream
Workspace Streaming
Apr 29, 2026
Jun 17, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arb...Show more
Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.Show less
1Fujitsu
1E Pares
Apr 29, 2026
Jun 3, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.
1Cisco
1Scientific Atlanta Webstar Dpc2100r2
Apr 29, 2026
May 26, 2010
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct...Show more
The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.Show less
1Novell
1Access Manager
Apr 29, 2026
May 26, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions.
1Vmware
1Tc Server
Apr 29, 2026
May 19, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for...Show more
com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for an encrypted (aka s2enc) password, which allows remote attackers to obtain JMX interface access via a blank password.Show less
1Consona
3Consona Dynamic Agent
Consona Live AssistanceConsona Subscriber Assistance
Apr 29, 2026
May 12, 2010
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empt...Show more
The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.Show less
1Toutvirtual
1Virtualiq
Apr 29, 2026
May 7, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management...Show more
ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the Web Console.Show less
1Moodle
1Moodle
Apr 29, 2026
Apr 29, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.
1Sitracker
1Support Incident Tracker
Apr 29, 2026
Apr 28, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
1Openx
1Openx
Apr 29, 2026
Apr 27, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/...Show more
Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files.Show less