CWE-287

Improper Authentication

High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Potential Impact

How to Fix

Architecture and Design

Use an authentication framework or library such as the OWASP ESAPI Authentication feature.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-287 vulnerabilities in your codebase.

Get Security Assessment