VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,534)

page 67 of 77
  • CVE-2020-8152MedNov 16, 2020
    risk 0.29cvss 4.4epss 0.00

    Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.

  • CVE-2019-4693MedAug 26, 2020
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.

  • CVE-2020-4593MedAug 24, 2020
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747.

  • CVE-2020-6239MedJun 10, 2020
    risk 0.29cvss 4.4epss 0.00

    Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.

  • CVE-2020-5263MedApr 9, 2020
    risk 0.29cvss 5.5epss 0.01

    auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the…

  • CVE-2014-4659MedFeb 20, 2020
    risk 0.29cvss 5.5epss 0.00

    Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

  • CVE-2014-4660MedFeb 20, 2020
    risk 0.29cvss 5.5epss 0.00

    Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb…

  • CVE-2019-10429MedSep 25, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10398MedSep 12, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10361MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10345MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

  • CVE-2019-11092MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0180MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0179MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0175MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0120MedMay 17, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient key protection vulnerability in silicon reference firmware for Intel(R) Pentium(R) Processor J Series, Intel(R) Pentium(R) Processor N Series, Intel(R) Celeron(R) J Series, Intel(R) Celeron(R) N Series, Intel(R) Atom(R) Processor A Series, Intel(R) Atom(R) Processor…

  • CVE-2017-1231MedOct 12, 2018
    risk 0.29cvss 4.4epss 0.00

    IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.

  • CVE-2017-12127MedMay 14, 2018
    risk 0.29cvss 4.4epss 0.00

    A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.

  • CVE-2026-62882MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.01

    Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-16104MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as…