VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 58 of 74
  • CVE-2026-54276MedJun 22, 2026
    risk 0.33cvss 6.1epss 0.00

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain…

  • CVE-2026-41715MedJun 9, 2026
    risk 0.33cvss 6.1epss 0.00

    In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty…

  • CVE-2026-23927MedMay 6, 2026
    risk 0.33cvss epss 0.00

    A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.

  • CVE-2026-34262MedApr 14, 2026
    risk 0.33cvss 5.0epss 0.00

    Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer

  • CVE-2025-36440MedMar 25, 2026
    risk 0.33cvss 5.1epss 0.00

    IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.

  • CVE-2024-39879MedJul 1, 2024
    risk 0.33cvss 5.0epss 0.00

    In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

  • CVE-2023-26221MedNov 8, 2023
    risk 0.33cvss 5.0epss 0.00

    The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful…

  • CVE-2023-32338MedSep 5, 2023
    risk 0.33cvss 5.1epss 0.00

    IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.

  • CVE-2022-41933MedNov 23, 2022
    risk 0.33cvss 6.2epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki 13.1RC1 and newer versions.…

  • CVE-2022-27544MedJul 19, 2022
    risk 0.33cvss 5.0epss 0.00

    BigFix Web Reports authorized users may see SMTP credentials in clear text.

  • CVE-2021-29253MedMay 26, 2021
    risk 0.33cvss 5.1epss 0.00

    The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.

  • CVE-2021-0212MedJan 15, 2021
    risk 0.33cvss 5.0epss 0.00

    An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their privileges over the system. This issue affects: Juniper…

  • CVE-2020-15157MedOct 16, 2020
    risk 0.33cvss 6.1epss 0.02

    In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise…

  • CVE-2020-7299MedSep 4, 2020
    risk 0.33cvss 5.0epss 0.00

    Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another user’s passwords on the same machine via triggering a…

  • CVE-2018-1075MedJun 12, 2018
    risk 0.33cvss 5.0epss 0.00

    ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the…

  • CVE-2026-11827MedJul 8, 2026
    risk 0.32cvss 4.9epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored…

  • CVE-2024-47271MedMay 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

  • CVE-2026-4819MedMar 31, 2026
    risk 0.32cvss 4.9epss 0.00

    In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

  • CVE-2026-0689MedMar 2, 2026
    risk 0.32cvss 4.9epss 0.00

    In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface,…

  • CVE-2026-1223MedJan 20, 2026
    risk 0.32cvss 4.9epss 0.00

    PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to allowing authenticated remote attackers to obtain SMTP plaintext passwords through the web frontend.