Fallos del tipo CWE-287

2418 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2017-12195MEDIUMA flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given nameEPSS 1.4%CVE-2022-23652HIGHPrivilege escalation using hop-by-hop Connection headerEPSS 1.4%CVE-2022-35248A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasseEPSS 1.4%CVE-2019-10150MEDIUMIt was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authenticatiEPSS 1.4%CVE-2022-28666MEDIUMWordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerabilityEPSS 1.4%CVE-2021-32693MEDIUMAuthentication granted with multiple firewallsEPSS 1.4%CVE-2021-1542HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 1.4%CVE-2023-37918MEDIUMAPI token authentication bypass in HTTP endpoints in DaprEPSS 1.4%CVE-2019-11272PlaintextPasswordEncoder authenticates encoded passwords that are nullEPSS 1.4%CVE-2020-14299A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketEPSS 1.4%CVE-2023-44324CRITICALZDI-CAN-21344: Adobe FrameMaker Publishing Server Authentication Bypass VulnerabilityEPSS 1.4%CVE-2023-36004HIGHWindows DPAPI (Data Protection Application Programming Interface) Spoofing VulnerabilityEPSS 1.4%CVE-2024-38225HIGHMicrosoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 1.4%CVE-2024-27923HIGHRemote Code Execution by uploading a phar file using frontmatterEPSS 1.4%CVE-2022-1248HIGHSAP Information System POST Request add_admin.php improper authenticationEPSS 1.4%CVE-2023-37544HIGHApache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoSEPSS 1.4%CVE-2021-26620HIGHIPTIME NAS2dual improper authentication vulnerabilityEPSS 1.4%CVE-2021-31917A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass auEPSS 1.3%CVE-2025-53793HIGHAzure Stack Hub Information Disclosure VulnerabilityEPSS 1.3%CVE-2024-23471CRITICALSolarWinds Access Rights Manager (ARM) CreateFile Directory Traversal Remote Code Execution VulnerabilityEPSS 1.3%