Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-6483CRITICALImproper Authentication Vulnerability in ADiTaaS EPSS 1.2%CVE-2024-49076HIGHWindows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2019-6527PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the passworEPSS 1.2%CVE-2026-1368HIGHVideo Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature GenerationEPSS 1.2%CVE-2021-41312HIGHAffected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service ManageEPSS 1.2%CVE-2022-46145HIGHauthentik vulnerable to unauthorized user creation and potential account takeoverEPSS 1.2%CVE-2020-24675CRITICALWeak Authentication in Symphony PlusEPSS 1.2%CVE-2023-6907MEDIUMcodelyfe Stupid Simple CMS Deletion Interface delete.php improper authenticationEPSS 1.2%CVE-2021-43444HIGHONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak EPSS 1.2%CVE-2022-46146MEDIUMPrometheus Exporter Toolkit vulnerable to basic authentication bypassEPSS 1.2%CVE-2021-22796A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected PEPSS 1.2%CVE-2020-15243CRITICALWebApi Authentication attribute missing in SmartstoreEPSS 1.2%CVE-2022-2133OAuth Single Sign On < 6.22.6 - Authentication BypassEPSS 1.2%CVE-2017-9630An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, EPSS 1.2%CVE-2019-18322A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.2%CVE-2019-18321A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.2%CVE-2024-38124CRITICALWindows Netlogon Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2024-40794MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6.EPSS 1.2%CVE-2023-52160MEDIUMThe implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be confEPSS 1.2%CVE-2025-49831CRITICALConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via Mis-configured Network DeviceEPSS 1.2%