Fallos del tipo CWE-287

2418 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2019-18341MEDIUMA vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the CoEPSS 1.6%CVE-2018-3822X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM trEPSS 1.6%CVE-2022-45922HIGHAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdmEPSS 1.6%CVE-2019-15987MEDIUMCisco WebEx Centers Username Enumeration Information Disclosure VulnerabilityEPSS 1.6%CVE-2019-18286A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes EPSS 1.6%CVE-2019-18287A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes EPSS 1.6%CVE-2021-44759Improper authentication vulnerability in TLS origin verificationEPSS 1.6%CVE-2025-55169CRITICALWeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'EPSS 1.6%CVE-2020-11020HIGHAuthentication and extension bypass in FayeEPSS 1.6%CVE-2014-5412Schneider Electric SCADA Expert ClearSCADA Improper AuthenticationEPSS 1.6%CVE-2007-4043CRITICALfile.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication EPSS 1.6%CVE-2017-6711A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker EPSS 1.6%CVE-2025-55241CRITICALAzure Entra ID Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2022-2197CRITICALExemys RME1EPSS 1.5%CVE-2024-21427HIGHWindows Kerberos Security Feature Bypass VulnerabilityEPSS 1.5%CVE-2018-12472HIGHAuthentication bypass in sibling checkEPSS 1.5%CVE-2022-20798CRITICALCisco Email Security Appliance and Cisco Secure Email and Web Manager External Authentication Bypass VulnerabilityEPSS 1.5%CVE-2021-36369HIGHAn issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-EPSS 1.5%CVE-2022-28321CRITICALThe Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn'tEPSS 1.5%CVE-2021-3652A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inEPSS 1.5%