VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 43 of 43
  • CVE-2022-39364MedOct 27, 2022
    risk 0.00cvss 4.0epss 0.00

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain…

  • CVE-2021-29481MedJun 29, 2021
    risk 0.00cvss 6.5epss 0.00

    Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side sessions results in unencrypted, but signed, data being set as cookie values. This means that if something sensitive goes into the session, it could be read…

  • CVE-2021-31855MedJun 2, 2021
    risk 0.00cvss 6.5epss 0.01

    KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server.…

  • CVE-2020-22783MedApr 28, 2021
    risk 0.00cvss 6.5epss 0.01

    Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.

  • CVE-2020-15085MedJun 30, 2020
    risk 0.00cvss 6.9epss 0.01

    In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the browser could extract the email and password. In versions…

  • CVE-2019-17106MedOct 8, 2019
    risk 0.00cvss 6.5epss 0.01

    In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.

  • CVE-2015-5537Aug 3, 2015
    risk 0.00cvss epss 0.01

    The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.

  • CVE-2010-0225Jan 7, 2010
    risk 0.00cvss epss 0.00

    SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.