Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-36093HIGHXWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution WizardEPSS 0.9%CVE-2020-5148SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potenEPSS 0.9%CVE-2019-5449A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidentialEPSS 0.9%CVE-2020-7856HIGHA vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficieEPSS 0.9%CVE-2023-4562CRITICALInformation Disclosure, Information Tampering and Authentication Bypass Vulnerability in MELSEC-F Series main moduleEPSS 0.9%CVE-2022-38336HIGHAn access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without aEPSS 0.8%CVE-2022-3465HIGHMediabridge Medialink index.asp improper authenticationEPSS 0.8%CVE-2022-46170HIGHCodeIgniter is vulnerable to improper authentication via Session HandlersEPSS 0.8%CVE-2022-39289CRITICALDatabase log access in ZoneMinderEPSS 0.8%CVE-2026-56185MEDIUMWindows Admin Center Information Disclosure VulnerabilityEPSS 0.8%CVE-2022-35135HIGHBoodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.EPSS 0.8%CVE-2021-41311HIGHAffected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access rEPSS 0.8%CVE-2024-1735CRITICALA vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentEPSS 0.8%CVE-2022-39255HIGHMatrix iOS SDK vulnerable ton Olm/Megolm protocol confusionEPSS 0.8%CVE-2022-39355CRITICALDiscourse Patreon vulnerable to improper validation of email during Patreon authenticationEPSS 0.8%CVE-2017-7557dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.EPSS 0.8%CVE-2022-21684MEDIUMUser can bypass approval when invited to DiscourseEPSS 0.8%CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.8%CVE-2025-43995CRITICALDell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attaEPSS 0.8%CVE-2025-44083CRITICALAn issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authenticationEPSS 0.8%