Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-12-12 CVE-2019-18319 Improper Authentication vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-287
7.5
2019-12-12 CVE-2019-18318 Improper Authentication vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-287
7.5
2019-12-12 CVE-2019-18317 Improper Authentication vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-287
7.5
2019-12-12 CVE-2019-18315 Improper Authentication vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-287
critical
9.8
2019-12-12 CVE-2019-18314 Improper Authentication vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-287
critical
9.8
2019-12-12 CVE-2019-18312 Improper Authentication vulnerability in Siemens Sppa-T3000 Ms3000 Migration Server
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions).
network
low complexity
siemens CWE-287
5.3
2019-12-11 CVE-2013-4593 Improper Authentication vulnerability in Omniauth-Facebook Project Omniauth-Facebook
RubyGem omniauth-facebook has an access token security vulnerability
network
low complexity
omniauth-facebook-project CWE-287
7.5
2019-12-10 CVE-2019-14870 Improper Authentication vulnerability in multiple products
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable.
5.4
2019-12-10 CVE-2013-2159 Improper Authentication vulnerability in Monkey-Project Monkey 1.2.1
Monkey HTTP Daemon: broken user name authentication
network
low complexity
monkey-project CWE-287
critical
9.8
2019-12-09 CVE-2019-18380 Improper Authentication vulnerability in Symantec Industrial Control System Protection 6.0.0
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.
low complexity
symantec CWE-287
6.5