Falhas do tipo CWE-287

2.418 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2017-12195MEDIUMA flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given nameEPSS 1.4%CVE-2022-23652HIGHPrivilege escalation using hop-by-hop Connection headerEPSS 1.4%CVE-2022-35248—A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasseEPSS 1.4%CVE-2019-10150MEDIUMIt was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authenticatiEPSS 1.4%CVE-2022-28666MEDIUMWordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerabilityEPSS 1.4%CVE-2021-32693MEDIUMAuthentication granted with multiple firewallsEPSS 1.4%CVE-2021-1542HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 1.4%CVE-2023-37918MEDIUMAPI token authentication bypass in HTTP endpoints in DaprEPSS 1.4%CVE-2019-11272—PlaintextPasswordEncoder authenticates encoded passwords that are nullEPSS 1.4%CVE-2020-14299—A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketEPSS 1.4%CVE-2023-44324CRITICALZDI-CAN-21344: Adobe FrameMaker Publishing Server Authentication Bypass VulnerabilityEPSS 1.4%CVE-2023-36004HIGHWindows DPAPI (Data Protection Application Programming Interface) Spoofing VulnerabilityEPSS 1.4%CVE-2024-38225HIGHMicrosoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 1.4%CVE-2024-27923HIGHRemote Code Execution by uploading a phar file using frontmatterEPSS 1.4%CVE-2022-1248HIGHSAP Information System POST Request add_admin.php improper authenticationEPSS 1.4%CVE-2023-37544HIGHApache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoSEPSS 1.4%CVE-2021-26620HIGHIPTIME NAS2dual improper authentication vulnerabilityEPSS 1.4%CVE-2021-31917—A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass auEPSS 1.3%CVE-2025-53793HIGHAzure Stack Hub Information Disclosure VulnerabilityEPSS 1.3%CVE-2024-23471CRITICALSolarWinds Access Rights Manager (ARM) CreateFile Directory Traversal Remote Code Execution VulnerabilityEPSS 1.3%