← Back
CWE-592

24 CVEs • Abstraction: Class

DEPRECATED: Authentication Bypass Issues

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

JSON object

Loading...

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
6Hibernate Validator
Jboss Enterprise Application PlatformSatellite+3 more
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernat...Show more
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().Show less
1Siemens
1Simatic Logon
May 13, 2026
Feb 22, 2017
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.
1Advantech
1Advantech Webaccess
May 6, 2026
Jul 19, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.
1I Gen
1Oplynx
Apr 29, 2026
Dec 31, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.