CWE-287 - CERT CVE

CWE-287 - Improper Authentication

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CAPEC ID Naziv
CAPEC-114 Authentication Abuse
CAPEC-115 Authentication Bypass
CAPEC-151 Identity Spoofing
CAPEC-194 Fake the Source of Data
CAPEC-22 Exploiting Trust in Client
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
CAPEC-593 Session Hijacking
CAPEC-633 Token Impersonation
CAPEC-650 Upload a Web Shell to a Web Server
CAPEC-94 Man in the Middle Attack