VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 33 of 43
  • CVE-2023-0690MedFeb 8, 2023
    risk 0.33cvss 5.0epss 0.00

    HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have been encrypted via the intended KMS. This…

  • CVE-2022-41933MedNov 23, 2022
    risk 0.33cvss 6.2epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki 13.1RC1 and newer versions.…

  • CVE-2021-1865MedSep 8, 2021
    risk 0.33cvss 5.0epss 0.01

    An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.

  • CVE-2026-3221MedFeb 25, 2026
    risk 0.32cvss 4.9epss 0.00

    Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.

  • CVE-2025-12772MedFeb 2, 2026
    risk 0.32cvss 4.9epss 0.00

    Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in…

  • CVE-2025-12680MedFeb 2, 2026
    risk 0.32cvss 4.9epss 0.00

    Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave…

  • CVE-2025-34270MedOct 30, 2025
    risk 0.32cvss 4.9epss 0.01

    Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface,…

  • CVE-2024-7259MedSep 26, 2024
    risk 0.32cvss 4.9epss 0.00

    A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.

  • CVE-2024-33470MedMay 24, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-20207MedJul 12, 2023
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An…

  • CVE-2023-22949MedApr 14, 2023
    risk 0.32cvss 4.9epss 0.00

    An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable…

  • CVE-2021-20162MedDec 30, 2021
    risk 0.32cvss 4.9epss 0.00

    Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaintext in the config files on the device. For example, /etc/config/cameo contains the admin password in plaintext.

  • CVE-2021-35035MedDec 29, 2021
    risk 0.32cvss 4.9epss 0.01

    A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.

  • CVE-2021-38911MedOct 19, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.

  • CVE-2021-33325MedAug 3, 2021
    risk 0.32cvss 4.9epss 0.01

    The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with…

  • CVE-2021-27233MedFeb 16, 2021
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password information for external systems is visible in cleartext. The Settings.asp page is affected by this issue.

  • CVE-2020-11415MedApr 27, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.

  • CVE-2019-18615MedDec 19, 2019
    risk 0.32cvss 4.9epss 0.00

    In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable…

  • CVE-2019-13947MedDec 12, 2019
    risk 0.32cvss 4.9epss 0.01

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges…

  • CVE-2025-53103MedJul 1, 2025
    risk 0.31cvss 5.8epss 0.00

    JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If…