VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 39 of 74
  • CVE-2024-28110HigMar 6, 2024
    risk 0.42cvss 7.5epss 0.01

    Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to…

  • CVE-2023-50291HigFeb 9, 2024
    risk 0.42cvss 7.5epss 0.03

    Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/properties, was only setup to…

  • CVE-2023-29055HigJan 29, 2024
    risk 0.42cvss 7.5epss 0.01

    In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible for network sniffers…

  • CVE-2022-39820MedDec 25, 2023
    risk 0.42cvss 6.5epss 0.01

    In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges…

  • CVE-2018-16153HigDec 12, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.

  • CVE-2023-49653MedNov 29, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

  • CVE-2020-17477MedOct 26, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. For example, a…

  • CVE-2023-27315MedOct 12, 2023
    risk 0.42cvss 6.5epss 0.00

    SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials

  • CVE-2022-44758MedOct 11, 2023
    risk 0.42cvss 6.5epss 0.00

    BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.

  • CVE-2022-44757MedOct 11, 2023
    risk 0.42cvss 6.5epss 0.00

    BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.

  • CVE-2023-25532MedSep 20, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to information disclosure.

  • CVE-2023-40347MedAug 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

  • CVE-2023-40345MedAug 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.

  • CVE-2022-4926MedJul 29, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-37951MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

  • CVE-2023-35348MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Active Directory Federation Service Security Feature Bypass Vulnerability

  • CVE-2023-31187MedMay 30, 2023
    risk 0.42cvss 6.5epss 0.00

    Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

  • CVE-2023-1763MedMay 17, 2023
    risk 0.42cvss 6.5epss 0.00

    Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.

  • CVE-2022-40685MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access.

  • CVE-2023-2335MedApr 27, 2023
    risk 0.42cvss 6.5epss 0.00

    Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.0.