When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,374 vulnerabilities with CWE-287
CVE-2013-4178
Google Authenticator Login Module < 6.x-1.2 / 7.x-1.4 - Authentication Bypass via OTP Replay
CVE-2013-2193
Apache HBase < 0.92.3, 0.94.x < 0.94.9 - Kerberos Authentication Bypass
CVE-2013-3977
IBM Sametime 8.x-8.5.2.1 and 9.x-9.0.0.1 - Meeting Room Enumeration via Valid User Names
CVE-2013-3046
IBM Sametime <8.5.2.1 & 9.0.0.1 - Info Disclosure
CVE-2013-2756
Apache CloudStack <4.0.2 & Citrix CloudPlatform <3.0.6 - Auth Bypass
CVE-2013-6806
OpenText Exceed OnDemand 8 - Man-in-the-Middle Authentication Downgrade via Crafted Response
CVE-2013-6766
OpenVAS Administrator 1.2-1.2.1 and 1.3-1.3.1 - Improper Authentication via OAP Version Request
CVE-2013-6765
OpenVAS Manager 3.0-3.0.6 and 4.0-4.0.3 - Unauthenticated OMP Command Execution via Version Request
CVE-2013-7379
ucdok/tomato < 0.0.5 and npm/tomato < 0.0.6 - Improper Authentication via Partial Access Key Match
CVE-2013-4471
OpenStack Horizon < 2013.2 - Unauthenticated Password Change via Identity v3 API
CVE-2013-4552
drupalauth < 1.2.1 - Unauthenticated Authentication Bypass via User Cookie
CVE-2013-4772
D-Link DIR-505L/DIR-826L - Auth Bypass
CVE-2013-4580
GitLab <5.4.2, <6.2.4, <6.2.1 - Auth Bypass
CVE-2013-7302
Ubercart module <6.2.13,7.3.6 - Session Fixation
CVE-2013-7366
SAP Software Deployment Manager - Denial of Service via Failed Authentication
CVE-2013-6031
Huawei E355 Firmware 21.157.37.01.910 - Unauthenticated Sensitive Information Disclosure via API
CVE-2013-7322
OATH Toolkit <2.4.1 - Info Disclosure
CVE-2013-4966
Puppet Enterprise <3.2.0 - Info Disclosure
CVE-2013-7183
Seowon Intech SWC-9100 - Unauthenticated Denial of Service via reboot.cgi
CVE-2013-6035
GateHouse and Multiple Satellite Terminals - Unauthenticated Remote Code Execution via TCP Port 1827
CVE-2013-4304
CentralAuth Extension for MediaWiki Authentication Bypass via Cached Cookie
CVE-2013-7137
CRITICAL
burden < 1.8.1 - Unauthenticated Authentication Bypass via Remember Me Cookie
CVSS 9.8
CVE-2013-2192
Apache Hadoop 2.x < 2.0.6-alpha, 0.23.x < 0.23.9, 1.x < 1.2.1 - Authentication Downgrade via RPC Protocol
CVE-2013-5429
IBM Tivoli Federated Identity Manager <6.2.2 - Info Disclosure
CVE-2013-6643
Google Chrome < 32.0.1700.77 - Unauthenticated Account Sync via Untrusted Signin Dialog
Details
Vulnerabilities
4,374
Exploit Likelihood
High