Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-39251HIGHMatrix Javascript SDK vulnerable to Olm/Megolm protocol confusionEPSS 1.0%CVE-2021-43834CRITICALIncorrect Authentication in elabftwEPSS 1.0%CVE-2024-0988MEDIUMSichuan Yougou Technology KuERP common.php checklogin improper authenticationEPSS 1.0%CVE-2021-38686HIGHImproper Authentication Vulnerability in VioStorEPSS 1.0%CVE-2026-58399HIGH@acastellon/auth has an authentication bypass via spoofable headers in validateToken()EPSS 1.0%CVE-2024-10511MEDIUMCWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local netwoEPSS 1.0%CVE-2022-39387CRITICALXWiki OIDC Authenticator vulnerable to OpenID login bypass due to improper authentication EPSS 1.0%CVE-2023-1460MEDIUMSourceCodester Online Pizza Ordering System Password Change improper authenticationEPSS 1.0%CVE-2025-58060HIGHcups has Authentication bypass with AuthType NegotiateEPSS 1.0%CVE-2017-6617A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) EPSS 1.0%CVE-2024-12510MEDIUMLDAP Authentication Sever Pass-back attackEPSS 1.0%CVE-2013-10004MEDIUMTelecommunication Software SAMwin Contact Center Suite Password SAMwinLIBVB.dll passwordScramble improper authenticationEPSS 1.0%CVE-2022-30238HIGHA CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacksEPSS 1.0%CVE-2021-34578CRITICALWAGO: Authentication Vulnerability in Web-Based ManagementEPSS 1.0%CVE-2017-20237CRITICALHirschmann Industrial HiVision Authentication Bypass Remote Code ExecutionEPSS 1.0%CVE-2023-25264HIGHAn issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter cEPSS 1.0%CVE-2022-1084HIGHSourceCodester One Church Management System Session userregister.php improper authenticationEPSS 1.0%CVE-2026-23600CRITICALA remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).EPSS 1.0%CVE-2024-5044MEDIUMEmlog Pro Cookie improper authenticationEPSS 1.0%CVE-2022-34155HIGHWordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.23.3 is vulnerable to Broken AuthenticationEPSS 1.0%