CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,372 vulnerabilities with CWE-287
CVE-2014-9043
ownCloud <5.0.18, <6.0.6, <7.0.3 - Auth Bypass
CVE-2014-8033
Cisco WebEx Meetings Server - Remote Privilege Escalation via API Request
CVE-2014-9578
VDG Security SENSE <2.3.13 - Auth Bypass
CVE-2014-8896
IBM InfoSphere Master Data Mgmt - Privilege Escalation
CVE-2014-8006
Cisco ISB8320-E High-Definition IP-Only DVR - Unauthenticated Authentication Bypass via Disaster Recovery TELNET Session
CVE-2014-7879
HP-UX B.11.11, B.11.23, B.11.31 - Authenticated Authentication Bypass
CVE-2014-7807
Apache CloudStack 4.3.x < 4.3.2 and 4.4.x < 4.4.2 - Unauthenticated Authentication Bypass via Login Request
CVE-2014-9217
Graylog2 < 0.91.3 - LDAP Authentication Bypass via Crafted Wildcards
CVE-2014-4631
RSA Adaptive Auth 6.0.2.1-7.1 P3 - Privilege Escalation
CVE-2014-9278
OpenSSH - Authenticated User Impersonation via .k5users File
CVE-2014-9184
ZTE ZXDSL 831CII - Unauthenticated Authentication Bypass via Direct CGI Request
CVE-2014-8424
ARRIS VAP2500 < 08.41 - Authentication Bypass via Improper Password Validation
CVE-2014-4831
IBM Security QRadar SIEM & QRadar Risk Manager <7.1 MR2 Patch 9 & <...
CVE-2014-6318
Microsoft Windows - Remote Desktop Protocol Improper Authentication
CVE-2014-2373
AXN-NET Ethernet module accessory 3.04 - Info Disclosure
CVE-2014-8472
CA Cloud Service Management < 2014 - Improper Authentication Token Verification
CVE-2014-6148
IBM Tivoli Application Dependency Discovery Manager 7.2.0.0-7.2.2.2 - Improper Authentication
CVE-2014-3623
Apache WSS4J < 1.6.17 and 2.x < 2.0.2 - Improper Authentication via SAML SubjectConfirmation Method
CVE-2014-8522
McAfee Network Data Loss Prevention < 9.3 - Unauthenticated MySQL Database Access
CVE-2014-8764
DokuWiki <2014-05-05a - Auth Bypass
CVE-2014-8763
DokuWiki <2014-05-05b - Auth Bypass
CVE-2014-8088
Zend Framework < 1.12.7 and 2.x < 2.2.8 - Authentication Bypass via Null Byte in LDAP Password
CVE-2014-6387
MantisBT < 1.2.17 - Unauthenticated Authentication Bypass via Null Byte in Password
CVE-2014-8329
Schrack Technik microControl Firmware < 1.7.0 - Unauthenticated Sensitive Information Exposure via ZTPUsrDtls.txt
CVE-2014-6116
IBM WebSphere MQ 8.0.0.1 - Authentication Bypass via MQTT Client JAASConfig Property
Details
Vulnerabilities 4,372
Exploit Likelihood High