VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (886)

page 45 of 45
  • CVE-2021-31855MedJun 2, 2021
    risk 0.00cvss 6.5epss 0.01

    KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server.…

  • CVE-2020-22783MedApr 28, 2021
    risk 0.00cvss 6.5epss 0.01

    Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.

  • CVE-2020-15085MedJun 30, 2020
    risk 0.00cvss 6.9epss 0.01

    In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the browser could extract the email and password. In versions…

  • CVE-2019-17106MedOct 8, 2019
    risk 0.00cvss 6.5epss 0.01

    In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.

  • CVE-2015-5537Aug 3, 2015
    risk 0.00cvss —epss 0.01

    The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.

  • CVE-2010-0225Jan 7, 2010
    risk 0.00cvss —epss 0.00

    SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.