CWE-522
Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (1,463)
page 53 of 74| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19539 | Med | 0.36 | 5.5 | 0.00 | Jan 27, 2020 | An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can… | ||
| CVE-2019-19696 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2020 | A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to… | ||
| CVE-2019-4335 | Med | 0.36 | 5.5 | 0.00 | Dec 30, 2019 | IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413. | ||
| CVE-2019-16572 | Med | 0.36 | 5.5 | 0.00 | Dec 17, 2019 | Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||
| CVE-2014-0241 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2019 | rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable | ||
| CVE-2012-5527 | Med | 0.36 | 5.5 | 0.01 | Nov 25, 2019 | Claws Mail vCalendar plugin: credentials exposed on interface | ||
| CVE-2019-16543 | Med | 0.36 | 5.5 | 0.00 | Nov 21, 2019 | Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||
| CVE-2010-4178 | Med | 0.36 | 5.5 | 0.00 | Nov 6, 2019 | MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console | ||
| CVE-2013-4423 | Med | 0.36 | 5.5 | 0.00 | Nov 4, 2019 | CloudForms stores user passwords in recoverable format | ||
| CVE-2019-4307 | Med | 0.36 | 5.5 | 0.00 | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 160987. | ||
| CVE-2019-0072 | Med | 0.36 | 5.6 | 0.00 | Oct 9, 2019 | An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information. This issue affects: Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R13;… | ||
| CVE-2019-10426 | Med | 0.36 | 5.5 | 0.00 | Sep 25, 2019 | Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||
| CVE-2019-10424 | Med | 0.36 | 5.5 | 0.00 | Sep 25, 2019 | Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||
| CVE-2019-10423 | Med | 0.36 | 5.5 | 0.00 | Sep 25, 2019 | Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||
| CVE-2019-10420 | Med | 0.36 | 5.5 | 0.00 | Sep 25, 2019 | Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||
| CVE-2019-10419 | Med | 0.36 | 5.5 | 0.00 | Sep 25, 2019 | Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||
| CVE-2019-4239 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2019 | IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465. | ||
| CVE-2019-6567 | Med | 0.36 | 5.5 | 0.00 | Jun 12, 2019 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All… | ||
| CVE-2019-11820 | Med | 0.36 | 5.5 | 0.00 | May 9, 2019 | Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline. | ||
| CVE-2018-11079 | Med | 0.36 | 5.5 | 0.00 | Oct 18, 2018 | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed… |
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can…
- risk 0.36cvss 5.5epss 0.00
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to…
- risk 0.36cvss 5.5epss 0.00
IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.
- risk 0.36cvss 5.5epss 0.00
Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- risk 0.36cvss 5.5epss 0.00
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
- risk 0.36cvss 5.5epss 0.01
Claws Mail vCalendar plugin: credentials exposed on interface
- risk 0.36cvss 5.5epss 0.00
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- risk 0.36cvss 5.5epss 0.00
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
- risk 0.36cvss 5.5epss 0.00
CloudForms stores user passwords in recoverable format
- risk 0.36cvss 5.5epss 0.00
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 160987.
- risk 0.36cvss 5.6epss 0.00
An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information. This issue affects: Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R13;…
- risk 0.36cvss 5.5epss 0.00
Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- risk 0.36cvss 5.5epss 0.00
Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- risk 0.36cvss 5.5epss 0.00
Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- risk 0.36cvss 5.5epss 0.00
Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- risk 0.36cvss 5.5epss 0.00
Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- risk 0.36cvss 5.5epss 0.00
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
- risk 0.36cvss 5.5epss 0.00
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All…
- risk 0.36cvss 5.5epss 0.00
Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.
- risk 0.36cvss 5.5epss 0.00
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed…