VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 64 of 74
  • CVE-2019-0180MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0179MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0175MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0120MedMay 17, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient key protection vulnerability in silicon reference firmware for Intel(R) Pentium(R) Processor J Series, Intel(R) Pentium(R) Processor N Series, Intel(R) Celeron(R) J Series, Intel(R) Celeron(R) N Series, Intel(R) Atom(R) Processor A Series, Intel(R) Atom(R) Processor…

  • CVE-2017-1231MedOct 12, 2018
    risk 0.29cvss 4.4epss 0.00

    IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.

  • CVE-2017-12127MedMay 14, 2018
    risk 0.29cvss 4.4epss 0.00

    A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.

  • CVE-2026-62882MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.01

    Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-16104MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as…

  • CVE-2026-2255MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by…

  • CVE-2026-22576MedApr 14, 2026
    risk 0.28cvss 4.3epss 0.00

    A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0…

  • CVE-2025-53669MedJul 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53665MedJul 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53661MedJul 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53660MedJul 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53657MedJul 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2024-47081MedJun 9, 2025
    risk 0.28cvss 5.3epss 0.01

    Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the…

  • CVE-2025-27926MedMar 10, 2025
    risk 0.28cvss 4.3epss 0.00

    In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.

  • CVE-2024-47161MedOct 8, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

  • CVE-2024-31899MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.

  • CVE-2024-34147MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.01

    Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.