VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 22 of 45
  • CVE-2019-19314HigJan 5, 2020
    risk 0.42cvss 7.5epss 0.01

    GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

  • CVE-2016-3192MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.

  • CVE-2019-5848MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.00

    Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-15508MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-15507MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.01

    In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-3753MedAug 20, 2019
    risk 0.42cvss 6.5epss 0.01

    Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with…

  • CVE-2019-13100MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.01

    The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_…

  • CVE-2019-13099MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.01

    The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.

  • CVE-2019-5810MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-1627MedJun 20, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is…

  • CVE-2018-2028MedJun 6, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.

  • CVE-2017-2672MedJun 21, 2018
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

  • CVE-2017-14990MedOct 3, 2017
    risk 0.42cvss 6.5epss 0.02

    WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access…

  • CVE-2024-20448MedOct 2, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of…

  • CVE-2024-31415MedSep 13, 2024
    risk 0.41cvss 6.3epss 0.00

    The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used…

  • CVE-2022-3089MedFeb 13, 2023
    risk 0.41cvss 6.3epss 0.00

    Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user…

  • CVE-2022-30626MedJul 18, 2022
    risk 0.41cvss 6.3epss 0.00

    Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text.

  • CVE-2021-35526MedSep 8, 2021
    risk 0.41cvss 6.3epss 0.00

    Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6…

  • CVE-2020-10706MedMay 12, 2020
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluster as any user who logged into…

  • CVE-2026-83551HigSep 1, 2026
    risk 0.40cvss 7.2epss 0.00

    Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and…