CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,924 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 14 of 99
- CVE-2012-3315MEDIUMCVSS v2 5.0EG 5.02012-11-08
The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads…
- CVE-2012-3356MEDIUMCVSS v2 5.0EG 5.02012-07-22
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
- CVE-2012-3416HIGHCVSS v2 10.0EG 10.02012-08-25
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
- CVE-2012-3462HIGHCVSS 8.8EG 8.82019-12-26
A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.
- CVE-2012-3472MEDIUMCVSS v2 6.4EG 6.42012-08-12
The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request.
- CVE-2012-3473MEDIUMCVSS v2 6.4EG 6.42012-08-12
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.
- CVE-2012-3492MEDIUMCVSS v2 6.4EG 6.42012-09-28
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by r…
- CVE-2012-3520LOWCVSS v2 1.9EG 1.92012-10-03
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message…
- CVE-2012-3721MEDIUMCVSS v2 5.0EG 5.02012-09-20
Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors.
- CVE-2012-3741LOWCVSS v2 1.9EG 1.92012-09-20
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via a…
- CVE-2012-3824HIGHCVSS 7.5EG 7.52020-01-10
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
- CVE-2012-3884MEDIUMCVSS v2 5.0EG 5.02012-07-26
AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to obtain access by sniffing the local wireless network and then replaying the authenticatio…
- CVE-2012-3885HIGHCVSS v2 7.5EG 7.52012-07-26
The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to obtain access via a brute-force attack.
- CVE-2012-4021MEDIUMCVSS v2 5.5EG 5.52012-11-08
MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, via unspecified vect…
- CVE-2012-4066MEDIUMCVSS v2 5.0EG 5.02013-03-08
The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows attackers to (1) delete or (2) upload snapshots.
- CVE-2012-4078HIGHCVSS v2 8.5EG 8.52013-09-24
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, …
- CVE-2012-4392HIGHCVSS v2 7.5EG 7.52012-09-05
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value.
- CVE-2012-4545MEDIUMCVSS v2 5.1EG 5.12013-01-03
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers …
- CVE-2012-4581MEDIUMCVSS v2 6.8EG 6.82012-08-22
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, whic…
- CVE-2012-4595HIGHCVSS v2 7.5EG 7.52012-08-22
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication and obtain an admin session ID via unspecified vectors.
- CVE-2012-4599HIGHCVSS v2 10.0EG 10.02012-08-22
McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbi…
- CVE-2012-4604MEDIUMCVSS v2 4.3EG 4.32012-08-23
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as…
- CVE-2012-4613MEDIUMCVSS v2 6.9EG 6.92012-11-16
EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access restrictions via a bru…
- CVE-2012-4614HIGHCVSS v2 9.3EG 9.32012-11-27
The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session.
- CVE-2012-4658MEDIUMCVSS v2 5.0EG 5.02014-04-23
The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.
- CVE-2012-4659HIGHCVSS v2 7.1EG 7.12012-10-29
The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.30) and 8.…
- CVE-2012-4688HIGHCVSS v2 7.5EG 7.52012-12-31
The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.
- CVE-2012-4741MEDIUMCVSS v2 5.0EG 5.02012-08-31
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the User-Name RADIUS a…
- CVE-2012-4926MEDIUMCVSS v2 6.4EG 6.42012-09-15
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
- CVE-2012-5003MEDIUMCVSS v2 6.8EG 6.82012-09-19
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter …
- CVE-2012-5032MEDIUMCVSS v2 6.4EG 6.42014-04-23
The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destinat…
- CVE-2012-5158MEDIUMCVSS v2 4.0EG 4.02014-03-14
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
- CVE-2012-5309MEDIUMCVSS v2 6.8EG 6.82012-10-08
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
- CVE-2012-5352MEDIUMCVSS v2 5.8EG 5.82012-10-09
Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
- CVE-2012-5353MEDIUMCVSS v2 5.8EG 5.82012-10-09
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
- CVE-2012-5758HIGHCVSS v2 7.8EG 7.82012-11-23
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified interface, which allows remote attackers to cause a denial of service (process exit) via unkn…
- CVE-2012-5858MEDIUMCVSS v2 4.3EG 4.32012-12-03
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.
- CVE-2012-5864HIGHCVSS v2 10.0EG 10.02012-11-23
These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.
- CVE-2012-5930MEDIUMCVSS v2 6.4EG 6.42012-12-24
The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of admin…
- CVE-2012-5940MEDIUMCVSS v2 4.3EG 4.32013-02-20
The WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza, when SSL is not enabled, allows remote attackers to discover credentials by sniffing the network during the authentication process.
- CVE-2012-5952MEDIUMCVSS v2 5.0EG 5.02013-02-20
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to…
- CVE-2012-5975HIGHCVSS v2 9.3EG 9.32012-12-04
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2 on UNIX and Linux, when old-style password authentication is enabled, allows remote attac…
- CVE-2012-6066HIGHCVSS v2 9.3EG 9.32012-12-04
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
- CVE-2012-6067HIGHCVSS v2 10.0EG 10.02012-12-04
freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
- CVE-2012-6274MEDIUMCVSS v2 5.0EG 5.02013-02-24
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.
- CVE-2012-6340MEDIUMCVSS 4.6EG 4.62020-02-06
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.
- CVE-2012-6354HIGHCVSS v2 7.5EG 7.52013-02-19
The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain superuser access via IP packets.
- CVE-2012-6437CRITICALCVSS 9.8EG 9.82013-01-24
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerabi…
- CVE-2012-6440MEDIUMCVSS 4.8EG 4.82013-01-24
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter p…
- CVE-2012-6451CRITICALCVSS 9.8EG 9.82020-01-24
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →