CAPEC Related Weakness
Brute Force
CWE-326 Inadequate Encryption Strength
CWE-330 Use of Insufficiently Random Values
CWE-521 Weak Password Requirements
Signature Spoofing by Key Recreation
CWE-330 Use of Insufficiently Random Values
Session Credential Falsification through Prediction
CWE-6 J2EE Misconfiguration: Insufficient Session-ID Length
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-285 Improper Authorization
CWE-290 Authentication Bypass by Spoofing
CWE-330 Use of Insufficiently Random Values
CWE-331 Insufficient Entropy
CWE-346 Origin Validation Error
CWE-384 Session Fixation
CWE-488 Exposure of Data Element to Wrong Session
CWE-539 Use of Persistent Cookies Containing Sensitive Information
CWE-693 Protection Mechanism Failure