VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 42 of 48
  • CVE-2023-42016MedFeb 9, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this…

  • CVE-2023-46447MedJan 20, 2024
    risk 0.28cvss 4.3epss 0.00

    The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.

  • CVE-2023-33187MedMay 26, 2023
    risk 0.28cvss 5.4epss 0.00

    Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates…

  • CVE-2022-32857MedAug 24, 2022
    risk 0.28cvss 4.3epss 0.00

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can…

  • CVE-2022-34804MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.00

    Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure.

  • CVE-2022-34801MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2017-20109MedJun 29, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the file /TeleoptiWFM/Administration/GetOneTenant of the component Administration. The manipulation leads to information disclosure…

  • CVE-2022-30115MedJun 2, 2022
    risk 0.28cvss 4.3epss 0.01

    Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the…

  • CVE-2021-29769MedJul 26, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user…

  • CVE-2021-1896MedJul 13, 2021
    risk 0.28cvss 4.3epss 0.00

    Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity

  • CVE-2021-23884MedApr 15, 2021
    risk 0.28cvss 4.3epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway…

  • CVE-2020-29662MedFeb 2, 2021
    risk 0.28cvss 5.3epss 0.01

    In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

  • CVE-2020-4597MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to…

  • CVE-2020-2251MedSep 1, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2020-2210MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-18248MedJun 29, 2020
    risk 0.28cvss 4.3epss 0.00

    BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credentials for connecting to the BIOTRONIK Remote Communication infrastructure.

  • CVE-2020-2157MedMar 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2020-2156MedMar 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2019-4743MedDec 20, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to…

  • CVE-2019-10740MedApr 7, 2019
    risk 0.28cvss 4.3epss 0.01

    In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can…