Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2018-3822—X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM trEPSS 1.6%CVE-2022-45922HIGHAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdmEPSS 1.6%CVE-2019-15987MEDIUMCisco WebEx Centers Username Enumeration Information Disclosure VulnerabilityEPSS 1.6%CVE-2019-18287—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes EPSS 1.6%CVE-2019-18286—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes EPSS 1.6%CVE-2021-44759—Improper authentication vulnerability in TLS origin verificationEPSS 1.6%CVE-2025-55169CRITICALWeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'EPSS 1.6%CVE-2020-11020HIGHAuthentication and extension bypass in FayeEPSS 1.6%CVE-2014-5412—Schneider Electric SCADA Expert ClearSCADA Improper AuthenticationEPSS 1.6%CVE-2007-4043CRITICALfile.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication EPSS 1.6%CVE-2017-6711—A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker EPSS 1.6%CVE-2025-55241CRITICALAzure Entra ID Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2022-2197CRITICALExemys RME1EPSS 1.5%CVE-2024-21427HIGHWindows Kerberos Security Feature Bypass VulnerabilityEPSS 1.5%CVE-2018-12472HIGHAuthentication bypass in sibling checkEPSS 1.5%CVE-2026-36829CRITICALAn authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validateEPSS 1.5%CVE-2022-20798CRITICALCisco Email Security Appliance and Cisco Secure Email and Web Manager External Authentication Bypass VulnerabilityEPSS 1.5%CVE-2021-36369HIGHAn issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-EPSS 1.5%CVE-2022-28321CRITICALThe Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn'tEPSS 1.5%CVE-2021-3652—A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inEPSS 1.5%