Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-24813MEDIUMAuthentication Bypass Using an Alternate Path or Channel in CreateWikiEPSS 1.0%CVE-2023-50275HIGHHPE OneView may allow clusterService Authentication Bypass resulting in denial of service.EPSS 1.0%CVE-2020-1718HIGHA flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized accesEPSS 1.0%CVE-2020-16239MEDIUMPhilips SureSigns VS4 Improper AuthenticationEPSS 1.0%CVE-2022-39250HIGHMatrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verificationEPSS 1.0%CVE-2023-1784MEDIUMjeecg-boot API Documentation improper authenticationEPSS 1.0%CVE-2022-2336CRITICALSofting Secure Integration Server Improper AuthenticationEPSS 1.0%CVE-2022-1101HIGHSourceCodester Royale Event Management System userregister.php improper authenticationEPSS 1.0%CVE-2022-36073HIGHRubyGems allows creation of users with arbitrary unverified emailsEPSS 1.0%CVE-2021-39138MEDIUMNew anonymous user session acts as if it's created with passwordEPSS 1.0%CVE-2023-6353MEDIUMTyler Technologies Civil and Criminal Electronic Filing Upload.aspx allows authentication bypassEPSS 1.0%CVE-2020-10754MEDIUMIt was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when cEPSS 1.0%CVE-2020-3197MEDIUMCisco Meetings App Missing TURN Server Credentials Expiration VulnerabilityEPSS 1.0%CVE-2023-6354MEDIUMTyler Technologies Magistrate Court Case Management Plus PDFViewer.aspx allows authentication bypassEPSS 1.0%CVE-2022-31686CRITICALVMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to WEPSS 1.0%CVE-2021-0193HIGHImproper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enabEPSS 1.0%CVE-2023-7210HIGHOneNav API improper authenticationEPSS 1.0%CVE-2025-27112MEDIUMNavidrome has authentication bypass in Subsonic API with non-existent usernameEPSS 1.0%CVE-2022-23769HIGHSecuever reverseWall-MDS Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-6768CRITICALAuthentication bypass vulnerability in Amazing Little PollEPSS 1.0%