Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2022-24813MEDIUMAuthentication Bypass Using an Alternate Path or Channel in CreateWikiEPSS 1.0%CVE-2023-50275HIGHHPE OneView may allow clusterService Authentication Bypass resulting in denial of service.EPSS 1.0%CVE-2020-1718HIGHA flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized accesEPSS 1.0%CVE-2020-16239MEDIUMPhilips SureSigns VS4 Improper AuthenticationEPSS 1.0%CVE-2022-39250HIGHMatrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verificationEPSS 1.0%CVE-2023-1784MEDIUMjeecg-boot API Documentation improper authenticationEPSS 1.0%CVE-2022-2336CRITICALSofting Secure Integration Server Improper AuthenticationEPSS 1.0%CVE-2022-1101HIGHSourceCodester Royale Event Management System userregister.php improper authenticationEPSS 1.0%CVE-2022-36073HIGHRubyGems allows creation of users with arbitrary unverified emailsEPSS 1.0%CVE-2021-39138MEDIUMNew anonymous user session acts as if it's created with passwordEPSS 1.0%CVE-2023-6353MEDIUMTyler Technologies Civil and Criminal Electronic Filing Upload.aspx allows authentication bypassEPSS 1.0%CVE-2020-10754MEDIUMIt was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when cEPSS 1.0%CVE-2020-3197MEDIUMCisco Meetings App Missing TURN Server Credentials Expiration VulnerabilityEPSS 1.0%CVE-2023-6354MEDIUMTyler Technologies Magistrate Court Case Management Plus PDFViewer.aspx allows authentication bypassEPSS 1.0%CVE-2022-31686CRITICALVMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to WEPSS 1.0%CVE-2021-0193HIGHImproper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enabEPSS 1.0%CVE-2023-7210HIGHOneNav API improper authenticationEPSS 1.0%CVE-2025-27112MEDIUMNavidrome has authentication bypass in Subsonic API with non-existent usernameEPSS 1.0%CVE-2022-23769HIGHSecuever reverseWall-MDS Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-6768CRITICALAuthentication bypass vulnerability in Amazing Little PollEPSS 1.0%