Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-12-21 CVE-2021-36350 Improper Authentication vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors.
network
low complexity
dell CWE-287
7.5
2021-12-20 CVE-2021-44525 Improper Authentication vulnerability in Zohocorp Manageengine Pam360
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
network
low complexity
zohocorp CWE-287
critical
9.8
2021-12-20 CVE-2021-44675 Improper Authentication vulnerability in Zohocorp Manageengine Servicedesk Plus MSP 10.5
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
network
low complexity
zohocorp CWE-287
critical
9.8
2021-12-20 CVE-2021-44676 Improper Authentication vulnerability in Zohocorp Manageengine Access Manager Plus 4.1/4.2
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.
network
low complexity
zohocorp CWE-287
critical
9.8
2021-12-17 CVE-2021-40851 Improper Authentication vulnerability in Tcman GIM 11.0/8.0
TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx.
network
low complexity
tcman CWE-287
7.5
2021-12-15 CVE-2021-43935 Improper Authentication vulnerability in Baxter products
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability.
network
low complexity
baxter CWE-287
critical
9.8
2021-12-14 CVE-2021-44937 Improper Authentication vulnerability in Glfusion 1.7.9
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php.
network
low complexity
glfusion CWE-287
5.3
2021-12-14 CVE-2021-44524 Improper Authentication vulnerability in Siemens Sipass Integrated and Siveillance Identity
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0).
network
low complexity
siemens CWE-287
critical
9.8
2021-12-13 CVE-2021-39064 Improper Authentication vulnerability in IBM Spectrum Copy Data Management 2.2.0.0/2.2.13
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console.
network
low complexity
ibm CWE-287
7.5
2021-12-09 CVE-2021-44514 Improper Authentication vulnerability in Zohocorp Manageengine Opmanager 12.5
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
network
low complexity
zohocorp CWE-287
critical
9.8