← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lightblog
1Lightblog
Apr 23, 2026
Oct 11, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.
2Broadcom
Ca
3Brightstor Arcserve Backup Laptops Desktops
Desktop Management SuiteProtection Suites
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete user...Show more
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.Show less
1Ruby Lang
1Ruby
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS r...Show more
The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.Show less
1Sun
2Java System Access Manager
Java System Application Server
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative...Show more
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.Show less
1Apple
2Iphone
Iphone Os
Apr 23, 2026
Sep 27, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) att...Show more
Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.Show less
1Roi Revolution
1Urchin
Apr 23, 2026
Sep 26, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid...Show more
report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.Show less
1Apache
1Geronimo
Apr 23, 2026
Sep 26, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
1Netsupport
1Netsupport Manager Client
Apr 23, 2026
Sep 24, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport Manager.
1Hp
1Hp Ux
Apr 23, 2026
Sep 20, 2007
N/A· v4
N/A· v3
9.0 HIGH· v2
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
1Cisco
3Video Surveillance Ip Gateway Encoder Decoder
Video Surveillance Sp IspVideo Surveillance Sp Isp Decoder Software
Apr 23, 2026
Sep 6, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveill...Show more
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote attackers to perform administrative actions, aka CSCsj31729.Show less
1Cisco
1Ios
Apr 23, 2026
Aug 31, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remo...Show more
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.Show less
1Apache
1Geronimo
Apr 23, 2026
Aug 27, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules,...Show more
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.Show less
1Ampache
1Ampache
Apr 23, 2026
Aug 20, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.
1Olate
1Olatedownload
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and...Show more
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.Show less
1Fedoraproject
1Commons
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
8.5 HIGH· v2
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password,...Show more
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password, which allows remote attackers to trigger a certain "unexpected / strange response" from an LDAP server, and (2) a reauthentication attempt that throws an exception, which allows remote attackers to trigger use of a cached authentication decision. NOTE: authentication can be bypassed by using vector 1 followed by vector 2, and possibly can be bypassed by using a single vector.Show less
1Mambo
1Mambo Open Source
Apr 23, 2026
Aug 8, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
1Securecomputing
1Securityreporter
Apr 23, 2026
Jul 27, 2007
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00.gif" sequence. NOTE: a separate traversa...Show more
file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00.gif" sequence. NOTE: a separate traversal vulnerability could be leveraged to download arbitrary files.Show less
1Virtual Hosting Control System
1Virtual Hosting Control System
Apr 23, 2026
Jul 25, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
1Zen Cart
1Zen Cart
Apr 23, 2026
Jul 6, 2007
N/A· v4
N/A· v3
8.5 HIGH· v2
Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.
1Apple
1Mac Os X
Apr 23, 2026
Jun 12, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Ac...Show more
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.Show less