VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 26 of 43
  • CVE-2024-45004MedSep 4, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix leak of blob encryption key Trusted keys unseal the key blob on load, but keep the sealed payload in the blob field so that every subsequent read (export) will simply convert this field…

  • CVE-2024-25024MedAug 15, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.

  • CVE-2024-25023MedJul 10, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.

  • CVE-2024-4840MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.

  • CVE-2024-29952MedApr 17, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

  • CVE-2024-24488MedFeb 7, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

  • CVE-2023-40238MedDec 7, 2023
    risk 0.36cvss 5.5epss 0.02

    A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a…

  • CVE-2023-4066MedSep 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.

  • CVE-2023-40715MedSep 13, 2023
    risk 0.36cvss 5.5epss 0.00

    A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.

  • CVE-2023-3950MedSep 1, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. Owners can now only write the…

  • CVE-2023-39210MedAug 8, 2023
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.

  • CVE-2023-32455MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

  • CVE-2023-32447MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

  • CVE-2023-32446MedJul 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

  • CVE-2023-32448MedMay 30, 2023
    risk 0.36cvss 5.5epss 0.00

    PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license PowerPath on different systems.

  • CVE-2023-20914MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User…

  • CVE-2023-25263MedMar 27, 2023
    risk 0.36cvss 5.5epss 0.00

    In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and…

  • CVE-2022-48310MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.

  • CVE-2023-24454MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2023-24442MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins…