VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 23 of 45
  • CVE-2026-8596HigMay 14, 2026
    risk 0.40cvss 7.2epss 0.01

    Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract the HMAC signing key from SageMaker API responses and forge valid integrity…

  • CVE-2026-7163MedApr 30, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters…

  • CVE-2025-55334MedOct 14, 2025
    risk 0.40cvss 6.2epss 0.00

    Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-40753MedAug 12, 2025
    risk 0.40cvss 6.2epss 0.00

    A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER…

  • CVE-2025-40752MedAug 12, 2025
    risk 0.40cvss 6.2epss 0.00

    A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER…

  • CVE-2024-24915MedJun 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

  • CVE-2025-4737MedMay 15, 2025
    risk 0.40cvss 6.2epss 0.00

    Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.

  • CVE-2024-39674MedJul 25, 2024
    risk 0.40cvss 6.2epss 0.00

    Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32474HigApr 18, 2024
    risk 0.40cvss 7.3epss 0.00

    Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser`. An attacker with access to…

  • CVE-2023-5384HigDec 18, 2023
    risk 0.40cvss 7.2epss 0.01

    A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.

  • CVE-2023-4400MedSep 13, 2023
    risk 0.40cvss 6.2epss 0.00

    A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG…

  • CVE-2023-22878MedMay 19, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.

  • CVE-2023-24964MedFeb 17, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.

  • CVE-2022-45098MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2022-42284MedJan 13, 2023
    risk 0.40cvss 6.2epss 0.00

    NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

  • CVE-2022-22789MedJan 25, 2022
    risk 0.40cvss 6.1epss 0.00

    Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an…

  • CVE-2021-22929MedAug 31, 2021
    risk 0.40cvss 6.1epss 0.00

    An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.

  • CVE-2018-1877MedNov 2, 2018
    risk 0.40cvss 6.2epss 0.00

    IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.

  • CVE-2026-53603HigSep 4, 2026
    risk 0.39cvss —epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a…

  • CVE-2025-46820HigMay 6, 2025
    risk 0.39cvss 7.1epss 0.00

    phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.yml workflow file uses actions/upload-artifact@v4 to upload the build artifact. This artifact is a zip of the current directory,…