Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-06-29 CVE-2019-18246 Improper Authentication vulnerability in Biotronik products
BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.
low complexity
biotronik CWE-287
4.3
2020-06-29 CVE-2019-20412 Improper Authentication vulnerability in Atlassian products
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types.
network
low complexity
atlassian CWE-287
5.3
2020-06-26 CVE-2020-14477 Improper Authentication vulnerability in Philips products
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.
local
low complexity
philips CWE-287
4.4
2020-06-24 CVE-2020-10278 Improper Authentication vulnerability in multiple products
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order.
4.6
2020-06-19 CVE-2017-18919 Improper Authentication vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3.
network
low complexity
mattermost CWE-287
5.3
2020-06-19 CVE-2017-18908 Improper Authentication vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2.
network
low complexity
mattermost CWE-287
critical
9.8
2020-06-19 CVE-2017-18906 Improper Authentication vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used.
network
low complexity
mattermost CWE-287
8.1
2020-06-19 CVE-2016-11074 Improper Authentication vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 3.0.0.
network
low complexity
mattermost CWE-287
critical
9.8
2020-06-19 CVE-2016-11072 Improper Authentication vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 3.0.2.
network
low complexity
mattermost CWE-287
6.5
2020-06-19 CVE-2019-20879 Improper Authentication vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7.
network
low complexity
mattermost CWE-287
4.3