VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 46 of 74
  • CVE-2019-10205MedJan 2, 2020
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.

  • CVE-2019-3800MedAug 5, 2019
    risk 0.41cvss 6.3epss 0.02

    CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is…

  • CVE-2025-15622MedApr 17, 2026
    risk 0.40cvss epss 0.00

    Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the…

  • CVE-2025-64998HigMar 24, 2026
    risk 0.40cvss 7.2epss 0.00

    Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

  • CVE-2021-47759MedJan 15, 2026
    risk 0.40cvss 6.2epss 0.00

    MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windows PowerShell process listing. Attackers can run a PowerShell command to retrieve the full command line of MTPutty processes,…

  • CVE-2023-50945MedJan 26, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

  • CVE-2024-22345MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.01

    IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 280192.

  • CVE-2024-28325MedApr 26, 2024
    risk 0.40cvss 6.1epss 0.00

    Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router settings.

  • CVE-2024-29216MedMar 25, 2024
    risk 0.40cvss 6.1epss 0.00

    Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the…

  • CVE-2021-38938MedMar 15, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 210989.

  • CVE-2023-4538MedFeb 15, 2024
    risk 0.40cvss 6.2epss 0.00

    The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This…

  • CVE-2024-21869MedFeb 2, 2024
    risk 0.40cvss 6.2epss 0.00

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local access to see them.

  • CVE-2023-47722MedDec 9, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

  • CVE-2022-4308MedApr 19, 2023
    risk 0.40cvss 6.1epss 0.00

    Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

  • CVE-2022-48433MedMar 29, 2023
    risk 0.40cvss 6.1epss 0.01

    In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.

  • CVE-2023-25686MedMar 21, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601.

  • CVE-2022-41732MedNov 28, 2022
    risk 0.40cvss 6.2epss 0.00

    IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.

  • CVE-2022-34837MedAug 24, 2022
    risk 0.40cvss 6.2epss 0.00

    Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.

  • CVE-2021-1537MedJun 4, 2021
    risk 0.40cvss 6.2epss 0.00

    A vulnerability in the installer software of Cisco ThousandEyes Recorder could allow an unauthenticated, local attacker to access sensitive information that is contained in the ThousandEyes Recorder installer software. This vulnerability exists because sensitive information is…

  • CVE-2020-14489MedJul 29, 2020
    risk 0.40cvss 6.2epss 0.01

    OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.