VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 17 of 27
  • CVE-2021-40650MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.01

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

  • CVE-2022-24045MedMay 20, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The application, after a successful login, sets…

  • CVE-2022-27225MedMar 16, 2022
    risk 0.42cvss 6.5epss 0.01

    Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During the sign-in process, Keycloak sets browser cookies that effectively provide remember-me functionality. For backwards…

  • CVE-2022-27206MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-32001MedJul 28, 2021
    risk 0.42cvss 6.5epss 0.00

    K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without…

  • CVE-2019-4471MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM…

  • CVE-2020-2250MedSep 1, 2020
    risk 0.42cvss 6.5epss 0.01

    Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2017-18909HigJun 19, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.

  • CVE-2010-3299MedNov 12, 2019
    risk 0.42cvss 6.5epss 0.01

    The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

  • CVE-2019-11664MedSep 18, 2019
    risk 0.42cvss 6.5epss 0.01

    Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

  • CVE-2019-11663MedSep 18, 2019
    risk 0.42cvss 6.5epss 0.00

    Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

  • CVE-2019-1003095MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003094MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003088MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Fabric Beta Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-9862MedMar 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the…

  • CVE-2018-3826MedSep 19, 2018
    risk 0.42cvss 6.5epss 0.01

    In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.

  • CVE-2018-4855MedJul 3, 2018
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). Unencrypted storage of passwords in the client configuration files and during network transmission could allow an attacker in a privileged position to obtain access passwords.

  • CVE-2018-5185MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2017-12716MedApr 25, 2018
    risk 0.42cvss 6.5epss 0.00

    Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers store the optional patient information…

  • CVE-2017-14953MedDec 1, 2017
    risk 0.42cvss 6.5epss 0.00

    HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentication. NOTE: Vendor states that this is not a…