VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 27 of 43
  • CVE-2023-24439MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2023-24055MedJan 22, 2023
    risk 0.36cvss 5.5epss 0.04

    KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against…

  • CVE-2022-47512MedDec 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected

  • CVE-2022-31697MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext…

  • CVE-2022-4312MedDec 12, 2022
    risk 0.36cvss 5.5epss 0.00

    A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer…

  • CVE-2022-33918MedOct 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user could potentially exploit this vulnerability and gain access to sensitive information.

  • CVE-2015-1931MedSep 29, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain…

  • CVE-2021-39009MedSep 1, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.

  • CVE-2021-3585MedAug 26, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.

  • CVE-2022-2569MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

  • CVE-2022-20219MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-22367MedJul 1, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.

  • CVE-2022-22478MedJun 30, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.

  • CVE-2021-41639MedJun 24, 2022
    risk 0.36cvss 5.5epss 0.00

    MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.

  • CVE-2022-22484MedMay 17, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker…

  • CVE-2022-29868MedMay 9, 2022
    risk 0.36cvss 5.5epss 0.00

    1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affected secrets include vault items and…

  • CVE-2022-23234MedMar 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext HANA credentials.

  • CVE-2020-14480MedFeb 24, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.

  • CVE-2022-23129MedJan 21, 2022
    risk 0.36cvss 5.5epss 0.00

    Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS GENESIS64 versions 10.90 to 10.97 allows a local authenticated attacker to gain authentication information and to access the database illegally.…

  • CVE-2021-31821MedJan 19, 2022
    risk 0.36cvss 5.5epss 0.00

    When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image