CWE-640

High likelihood

Weak Password Recovery Mechanism for Forgotten Password

Parent: CWE-1390 - Weak Authentication

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

258 vulnerabilities with CWE-640
CVE-2017-2614 MEDIUM
Redhat Enterprise Virtualization - Password Reset Weakness
CVSS 6.8
CVE-2017-0921 HIGH
GitLab <10.1.6-10.3.4 - Info Disclosure
CVSS 8.1
CVE-2017-12161 HIGH
Keycloak <3.4.2 - Info Disclosure
CVSS 8.8
CVE-2017-8916 HIGH
CIS-CAT Pro Dashboard <1.0.4 - Privilege Escalation
CVSS 7.8
CVE-2017-1000141 MEDIUM
Mahara <18.10.0 - Privilege Escalation
CVSS 6.5
CVE-2017-17097 CRITICAL
GPS Tracking Software 2.x - Info Disclosure
CVSS 9.8
CVE-2017-14005 HIGH
ProMinent MultiFLEX M10a - Privilege Escalation
CVSS 8.8
CVE-2017-7551 CRITICAL
389-ds-base <1.3.5.19,1.3.6.7 - Info Disclosure
CVSS 9.8
CVE-2017-12851 HIGH
Kanboard < 1.0.45 - Password Reset Weakness
CVSS 8.8
CVE-2017-12850 HIGH
Kanboard < 1.0.45 - Password Reset Weakness
CVSS 8.8
CVE-2017-8613 HIGH
Microsoft Azure Active Directory Connect - Password Reset Weakness
CVSS 8.1
CVE-2017-7629 HIGH
QNAP QTS <4.2.6 - Info Disclosure
CVSS 7.5
CVE-2017-9543 HIGH
EFS Software Easy Chat Server <3.1 - RCE
CVSS 7.5
CVE-2017-7731 HIGH
Fortinet FortiPortal <4.0.0 - Info Disclosure
CVSS 7.5
CVE-2017-8295 MEDIUM
Wordpress < 4.7.4 - Password Reset Weakness
CVSS 5.9
CVE-2017-8385 MEDIUM
Craftcms Craft Cms < 2.6.2974 - Password Reset Weakness
CVSS 5.3
CVE-2017-7615 HIGH
MantisBT <2.3.0 - Info Disclosure
CVSS 8.8
CVE-2017-2766 CRITICAL
EMC Documentum Eroom - Password Reset Weakness
CVSS 9.8
CVE-2017-5594 HIGH
Pagekit < 1.0.10 - Password Reset Weakness
CVSS 7.5
CVE-2016-8716 HIGH
Moxa AWK-3131A <1.1 - Info Disclosure
CVSS 7.5
CVE-2016-7038 HIGH
Moodle < 2.7.15 - Password Reset Weakness
CVSS 7.3
CVE-2016-2349 HIGH
BMC Remedy Action Request System - Password Reset Weakness
CVSS 7.5
CVE-2016-5997 MEDIUM
IBM Tealeaf Customer Experience <9.0.1-9.0.2 - Info Disclosure
CVSS 6.5
CVE-2016-5996 HIGH
IBM Tealeaf Customer Experience <9.0.1.1117 - Info Disclosure
CVSS 7.5
CVE-2015-10071 LOW
gitter-badger ezpublish-modern-legacy - Weak Password Recovery
CVSS 2.6
Details
Vulnerabilities 258
Exploit Likelihood High