Fallos del tipo CWE-287

2415 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2017-7931In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acceEPSS 2.5%CVE-2019-18337CRITICALA vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authEPSS 2.5%CVE-2026-11374CRITICALAccount Takeover via Predictable SSO Ticket GenerationEPSS 2.5%CVE-2024-49757HIGHZitadel User Registration Bypass VulnerabilityEPSS 2.5%CVE-2018-0121A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could alloEPSS 2.5%CVE-2019-18315A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 2.5%CVE-2017-13995An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does nEPSS 2.5%CVE-2025-32975CRITICALQuest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 EPSS 2.5%KEVCVE-2020-10888MEDIUMThis vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC17EPSS 2.5%CVE-2023-22964CRITICALZoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication iEPSS 2.4%CVE-2017-7420An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer anEPSS 2.4%CVE-2017-11428HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.4%CVE-2022-48066CRITICALAn issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.EPSS 2.4%CVE-2020-3125HIGHCisco Adaptive Security Appliance Software Kerberos Authentication Bypass VulnerabilityEPSS 2.4%CVE-2017-11430HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.4%CVE-2018-1112HIGHglusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster clientEPSS 2.4%CVE-2021-43786CRITICALAPI token verification can be bypassedEPSS 2.4%CVE-2020-3361HIGHCisco Webex Meetings and Cisco Webex Meetings Server Token Handling Unauthorized Access VulnerabilityEPSS 2.4%CVE-2022-24883HIGHFreeRDP Server authentication might allow invalid credentials to passEPSS 2.4%CVE-2022-39205CRITICALAccess Control Bypass in OnedevEPSS 2.4%