VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 21 of 45
  • CVE-2021-33716MedSep 14, 2021
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1.1). An attacker with access to the subnet of the affected device could retrieve sensitive information stored in cleartext.

  • CVE-2020-4980MedJul 16, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.

  • CVE-2021-21734MedMay 28, 2021
    risk 0.42cvss 6.5epss 0.01

    Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10 F822 V1.4.3T6, ZXA10 F819 V1.2.1T5, ZXA10 F832 V1.1.1T7, ZXA10 F839 V1.1.0T8,…

  • CVE-2021-29683MedMay 20, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.

  • CVE-2021-21547MedApr 30, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere Administrator are stored in plain text. A local malicious…

  • CVE-2021-27210MedFeb 13, 2021
    risk 0.42cvss 6.5epss 0.01

    TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.

  • CVE-2021-20358MedFeb 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files. IBM X-Force ID: 194965.

  • CVE-2021-1265MedJan 20, 2021
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to the configuration archives files being…

  • CVE-2020-29501MedJan 5, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2020-29489MedJan 5, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with…

  • CVE-2019-4738MedDec 10, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.

  • CVE-2020-28917MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext…

  • CVE-2020-4619MedSep 22, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.

  • CVE-2020-17495HigAug 11, 2020
    risk 0.42cvss 7.5epss 0.01

    django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

  • CVE-2019-13021MedMay 14, 2020
    risk 0.42cvss 6.5epss 0.01

    The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation script, after the administrator has…

  • CVE-2020-2164MedMar 25, 2020
    risk 0.42cvss 6.5epss 0.01

    Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.

  • CVE-2019-16062MedMar 19, 2020
    risk 0.42cvss 6.5epss 0.01

    NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.

  • CVE-2019-10682HigMar 18, 2020
    risk 0.42cvss 7.5epss 0.01

    django-nopassword before 5.0.0 stores cleartext secrets in the database.

  • CVE-2019-14886MedMar 5, 2020
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could…

  • CVE-2020-6794MedMar 2, 2020
    risk 0.42cvss 6.5epss 0.01

    If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60.…