Fallos del tipo CWE-287

2397 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-45148HIGHAdobe Commerce | Improper Authentication (CWE-287)EPSS 0.7%CVE-2026-5229CRITICALReceive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth CallbackEPSS 0.7%CVE-2026-62827HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2021-40507CRITICALAn issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not EPSS 0.7%CVE-2021-40506CRITICALAn issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not EPSS 0.7%CVE-2020-5425HIGHUser Impersonation possible in Tanzu SSOEPSS 0.7%CVE-2023-30945CRITICALCVE-2023-30945 EPSS 0.7%CVE-2026-86293MEDIUMSourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authenticationEPSS 0.7%CVE-2026-19977CRITICALEFM ipTIME A3004T Session Validation httpcon_check_session_url improper authenticationEPSS 0.7%CVE-2026-46840CRITICALVulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. EasilEPSS 0.7%CVE-2023-44252HIGH** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and versiEPSS 0.7%CVE-2022-23654HIGHImproper write access check in Requarks/wikiEPSS 0.7%CVE-2026-48929HIGHRocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletionEPSS 0.7%CVE-2023-45801HIGHImproper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0. EPSS 0.7%CVE-2026-16083MEDIUMSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replayEPSS 0.7%CVE-2024-28735HIGHUnit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows anEPSS 0.7%CVE-2022-22523HIGHCarlo Gavazzi UWP 3.0 WebApp allows for authentication bypassEPSS 0.7%CVE-2023-1617CRITICALImproper Authentication Mechanism in B&R VC4 VisualizationEPSS 0.7%CVE-2022-38180MEDIUMIn JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some casesEPSS 0.7%CVE-2023-4373CRITICAL Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 anEPSS 0.7%