ClassDraftTop 25 #14
CWE-287Improper Authentication
Category: auth
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Common consequences· 1
- Integrity / Confidentiality / Availability / Access Control — Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or CommandsThis weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
Potential mitigations· 1
- [Architecture and Design]Use an authentication framework or library such as the OWASP ESAPI Authentication feature.
Related CAPEC attack patterns· 10
References
Exploits (incoming)9
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Upload a Web Shell to a Web Servercapec-650 | 100% | live |
| AttackPattern | Authentication Abusecapec-114 | 100% | live |
| AttackPattern | Utilizing REST's Trust in the System Resource to Obtain Sensitive Datacapec-57 | 100% | live |
| AttackPattern | Exploiting Trust in Clientcapec-22 | 100% | live |
| AttackPattern | Fake the Source of Datacapec-194 | 100% | live |
| AttackPattern | Session Hijackingcapec-593 | 100% | live |
| AttackPattern | Authentication Bypasscapec-115 | 100% | live |
| AttackPattern | Adversary in the Middle (AiTM)capec-94 | 100% | live |
| AttackPattern | Token Impersonationcapec-633 | 100% | live |
Compliance frameworks addressing this (incoming)32
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | nist_csf-rs | 100% | live |
| ComplianceControl | iso27001-a.8.21 | 100% | live |
| ComplianceControl | iso27001-a.8.29 | 100% | live |
| ComplianceControl | dora-art24 | 100% | live |
| ComplianceControl | owasp_top10-a07 | 100% | live |
| ComplianceControl | dora-art17 | 100% | live |
| ComplianceControl | iso27701-a.7.3.6 | 100% | live |
| ComplianceControl | cis_v8-18 | 100% | live |
| ComplianceControl | iso27001-a.8.26 | 100% | live |
| ComplianceControl | nis2-art21e | 100% | live |
| ComplianceControl | cis_v8-13 | 100% | live |
| ComplianceControl | pci_dss_v4-r6 | 100% | live |
| ComplianceControl | owasp_api_top10-api10 | 100% | live |
| ComplianceControl | iso27001-a.8.5 | 100% | live |
| ComplianceControl | pci_dss_v4-r9 | 100% | live |
| ComplianceControl | iso27701-a.7.3.1 | 100% | live |
| ComplianceControl | iso27001-a.5.23 | 100% | live |
| ComplianceControl | tiber_eu-closure | 100% | live |
| ComplianceControl | dora-art6 | 100% | live |
| ComplianceControl | cra-art14 | 100% | live |
| ComplianceControl | cis_v8-16 | 100% | live |
| ComplianceControl | pci_dss_v4-r8 | 100% | live |
| ComplianceControl | iso27701-a.7.5.1 | 100% | live |
| ComplianceControl | pci_dss_v4-r4 | 100% | live |
| ComplianceControl | nis2-art21i | 100% | live |
| ComplianceControl | dora-art25 | 100% | live |
| ComplianceControl | nis2-art21b | 100% | live |
| ComplianceControl | pci_dss_v4-r11 | 100% | live |
| ComplianceControl | tiber_eu-testing | 100% | live |
| ComplianceControl | dora-art11 | 100% | live |
Showing top 30 of 32 by confidence. Click any target to see the full neighbourhood.
(incoming)109
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-0070cve-2025-0070 | 0% | live |
| Vulnerability | CVE-2025-0637cve-2025-0637 | 0% | live |
| Vulnerability | CVE-2025-0890cve-2025-0890 | 0% | live |
| Vulnerability | CVE-2025-10293cve-2025-10293 | 0% | live |
| Vulnerability | CVE-2025-1044cve-2025-1044 | 0% | live |
| Vulnerability | CVE-2025-10906cve-2025-10906 | 0% | live |
| Vulnerability | CVE-2025-1104cve-2025-1104 | 0% | live |
| Vulnerability | CVE-2025-11130cve-2025-11130 | 0% | live |
| Vulnerability | CVE-2025-11192cve-2025-11192 | 0% | live |
| Vulnerability | CVE-2025-11287cve-2025-11287 | 0% | live |
| Vulnerability | CVE-2025-11529cve-2025-11529 | 0% | live |
| Vulnerability | CVE-2025-11625cve-2025-11625 | 0% | live |
| Vulnerability | CVE-2025-11661cve-2025-11661 | 0% | live |
| Vulnerability | CVE-2025-11942cve-2025-11942 | 0% | live |
| Vulnerability | CVE-2025-12374cve-2025-12374 | 0% | live |
| Vulnerability | CVE-2025-14002cve-2025-14002 | 0% | live |
| Vulnerability | CVE-2025-1475cve-2025-1475 | 0% | live |
| Vulnerability | CVE-2025-14908cve-2025-14908 | 0% | live |
| Vulnerability | CVE-2025-14942cve-2025-14942 | 0% | live |
| Vulnerability | CVE-2025-15069cve-2025-15069 | 0% | live |
| Vulnerability | CVE-2025-15099cve-2025-15099 | 0% | live |
| Vulnerability | CVE-2025-15457cve-2025-15457 | 0% | live |
| Vulnerability | CVE-2025-15458cve-2025-15458 | 0% | live |
| Vulnerability | CVE-2025-15484cve-2025-15484 | 0% | live |
| Vulnerability | CVE-2025-1723cve-2025-1723 | 0% | live |
| Vulnerability | CVE-2025-20160cve-2025-20160 | 0% | live |
| Vulnerability | CVE-2025-21450cve-2025-21450 | 0% | live |
| Vulnerability | CVE-2025-22146cve-2025-22146 | 0% | live |
| Vulnerability | CVE-2025-22236cve-2025-22236 | 0% | live |
| Vulnerability | CVE-2025-22477cve-2025-22477 | 0% | live |
Showing top 30 of 109 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.