VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 53 of 74
  • CVE-2019-19539MedJan 27, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can…

  • CVE-2019-19696MedJan 18, 2020
    risk 0.36cvss 5.5epss 0.00

    A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to…

  • CVE-2019-4335MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.

  • CVE-2019-16572MedDec 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2014-0241MedDec 13, 2019
    risk 0.36cvss 5.5epss 0.00

    rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

  • CVE-2012-5527MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.01

    Claws Mail vCalendar plugin: credentials exposed on interface

  • CVE-2019-16543MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2010-4178MedNov 6, 2019
    risk 0.36cvss 5.5epss 0.00

    MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console

  • CVE-2013-4423MedNov 4, 2019
    risk 0.36cvss 5.5epss 0.00

    CloudForms stores user passwords in recoverable format

  • CVE-2019-4307MedOct 29, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 160987.

  • CVE-2019-0072MedOct 9, 2019
    risk 0.36cvss 5.6epss 0.00

    An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information. This issue affects: Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R13;…

  • CVE-2019-10426MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10424MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10423MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10420MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10419MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-4239MedJun 14, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.

  • CVE-2019-6567MedJun 12, 2019
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All…

  • CVE-2019-11820MedMay 9, 2019
    risk 0.36cvss 5.5epss 0.00

    Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.

  • CVE-2018-11079MedOct 18, 2018
    risk 0.36cvss 5.5epss 0.00

    Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed…