VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 21 of 43
  • CVE-2020-28917MedNov 18, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext…

  • CVE-2020-4619MedSep 22, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.

  • CVE-2020-17495HigAug 11, 2020
    risk 0.42cvss 7.5epss 0.01

    django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

  • CVE-2019-13021MedMay 14, 2020
    risk 0.42cvss 6.5epss 0.01

    The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation script, after the administrator has…

  • CVE-2020-2164MedMar 25, 2020
    risk 0.42cvss 6.5epss 0.01

    Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.

  • CVE-2019-16062MedMar 19, 2020
    risk 0.42cvss 6.5epss 0.01

    NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.

  • CVE-2019-10682HigMar 18, 2020
    risk 0.42cvss 7.5epss 0.01

    django-nopassword before 5.0.0 stores cleartext secrets in the database.

  • CVE-2019-14886MedMar 5, 2020
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could…

  • CVE-2020-6794MedMar 2, 2020
    risk 0.42cvss 6.5epss 0.01

    If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60.…

  • CVE-2019-19314HigJan 5, 2020
    risk 0.42cvss 7.5epss 0.01

    GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

  • CVE-2016-3192MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.

  • CVE-2019-5848MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.00

    Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-15508MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-15507MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-3753MedAug 20, 2019
    risk 0.42cvss 6.5epss 0.01

    Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with…

  • CVE-2019-13100MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.01

    The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_…

  • CVE-2019-13099MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.01

    The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.

  • CVE-2019-5810MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-1627MedJun 20, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is…

  • CVE-2018-2028MedJun 6, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.