CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,372 vulnerabilities with CWE-287
CVE-2014-4444
Apple OS X <10.10 - Privilege Escalation
CVE-2014-4435
Apple OS X <10.10 - Info Disclosure
CVE-2014-4425
Apple OS X <10.10 - Info Disclosure
CVE-2014-2066
Jenkins <1.551-1.532.2 - Info Disclosure
CVE-2014-2062
Jenkins <1.551-LTS <1.532.2 - Auth Bypass
CVE-2014-2927
F5 Arx - Authentication Bypass
CVE-2014-6379
Juniper Junos <11.4-R12,<12.1-R10,... - Privilege Escalation
CVE-2014-3402
Cisco Intrusion Prevention System < 7.0(8)E4 - Denial of Service via Crafted Connection Request
CVE-2014-3393
Cisco Adaptive Security Appliance Software - Improper Authentication in Clientless SSL VPN Portal Customization
CVE-2014-6632
Joomla! <2.5.25-3.3.4 - Auth Bypass
CVE-2014-5300
Adaptive Computing Moab < 7.2.9 and 8 < 8.0.0 - Unauthenticated Authentication Bypass via Message Without Signature
CVE-2014-0074
Apache Shiro 1.x < 1.2.3 - Authentication Bypass via Empty LDAP Credentials
CVE-2014-3106
IBM Rational ClearQuest 7.1-8.0.1 - Unauthenticated Authentication Bypass via Help Server Administration Feature
CVE-2014-3101
IBM Rational ClearQuest 7.1-8.0.1 - Improper Authentication via Web Login Form
CVE-2014-5412
Schneider Electric ClearSCADA 2010 R3-2014 R1 - Unauthenticated Database Record Read via Guest Account
CVE-2014-2685
Zend Framework < 1.12.4 - Improper Authentication via OpenID Assertion
CVE-2014-4619
EMC RSA IMG <6.5.1P11-6.8.1P07 - Auth Bypass
CVE-2014-0482
Django <1.4.14-1.7 - Auth Bypass
CVE-2014-4325
Little Kernel Bootloader - Authentication Bypass via Fastboot Boot Command
CVE-2014-0973
Little Kernel Bootloader - Improper Authentication via Inconsistent Digest Size Check
CVE-2014-5385
Shopizer < 1.1.5 - Unauthenticated Brute Force Attack via Unrestricted Authentication Attempts
CVE-2014-5175
SAP Solution Manager 7.1 - Authentication Bypass via Verb Tampering
CVE-2014-3895
I-O DATA TS-WLCAM, TS-WLCAM/V, TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, and TS-WLC2 Cameras - Authentication Bypass
CVE-2014-3552
Moodle < 2.3.11, 2.4.x < 2.4.11, 2.5.x < 2.5.7 - Authenticated Session Hijacking via Shibboleth Plugin
CVE-2014-4725
MailPoet Newsletters <2.6.7 - Auth Bypass
Details
Vulnerabilities 4,372
Exploit Likelihood High