Back to Labs
Weakness (CWE)

CWE-287

Improper Authentication

About

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Common consequences

  • Integrity, Confidentiality, Availability, Access Control → Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands

Mitigations

  • Architecture and Design: Use an authentication framework or library such as the OWASP ESAPI Authentication feature.

CVEs with this weakness

Frequently asked questions

What is CWE-287?

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

How likely is CWE-287 to be exploited?

MITRE rates the likelihood of exploit for CWE-287 as high.

Which platforms does CWE-287 affect?

CWE-287 has been observed on: Not OS-Specific, Not Technology-Specific, Web Based, ICS/OT.

How many CVEs does Rainforest track for CWE-287?

Rainforest Labs currently tracks 4 published CVEs mapped to CWE-287. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.