VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 20 of 45
  • CVE-2023-30531MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2023-30528MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2023-0614MedApr 3, 2023
    risk 0.42cvss 6.5epss 0.01

    The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

  • CVE-2022-31405MedFeb 27, 2023
    risk 0.42cvss 6.5epss 0.01

    MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.

  • CVE-2022-44644MedJan 31, 2023
    risk 0.42cvss 6.5epss 0.01

    In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the parameters in the…

  • CVE-2022-45897MedJan 31, 2023
    risk 0.42cvss 6.5epss 0.00

    On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.

  • CVE-2023-22332MedJan 30, 2023
    risk 0.42cvss 6.5epss 0.01

    Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of…

  • CVE-2023-24450MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-45439MedJan 17, 2023
    risk 0.42cvss 6.5epss 0.00

    A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has been retrieved from the…

  • CVE-2022-34339MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.00

    "IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."

  • CVE-2022-2805MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.

  • CVE-2022-3540MedOct 17, 2022
    risk 0.42cvss 6.5epss 0.00

    An issue has been discovered in hunter2 affecting all versions before 2.1.0. Improper handling of auto-completion input allows an authenticated attacker to extract other users email addresses

  • CVE-2022-33928MedAug 10, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the…

  • CVE-2022-29620MedJun 7, 2022
    risk 0.42cvss 6.5epss 0.02

    FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability

  • CVE-2021-45491MedMar 28, 2022
    risk 0.42cvss 6.5epss 0.01

    3CX System through 2022-03-17 stores cleartext passwords in a database.

  • CVE-2021-35036MedMar 1, 2022
    risk 0.42cvss 6.5epss 0.00

    A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.

  • CVE-2021-34544MedDec 7, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device. Fixed with 3.0.0-60 11.10.2013 for SL 200,…

  • CVE-2021-29786MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.

  • CVE-2021-38915MedOct 12, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.

  • CVE-2021-38150MedSep 14, 2021
    risk 0.42cvss 6.5epss 0.01

    When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials. This would allow the attacker…