VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,534)

page 73 of 77
  • CVE-2020-2209MedJul 2, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2020-2182MedMay 6, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.

  • CVE-2020-2126MedFeb 12, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.

  • CVE-2020-2095MedJan 15, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-0183LowJun 13, 2019
    risk 0.21cvss 3.3epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0182LowJun 13, 2019
    risk 0.21cvss 3.3epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2018-1000402MedJul 9, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to have been fixed in 1.20…

  • CVE-2018-1000057MedFeb 9, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to…

  • CVE-2025-62312LowMay 14, 2026
    risk 0.20cvss 3.0epss 0.00

    HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse, especially if not combined with secure transmission practices.

  • CVE-2025-6526LowJun 23, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects some unknown processing of the component HTTP Server. The manipulation leads to insufficiently protected credentials. The attack can only be done within the…

  • CVE-2024-45744LowSep 27, 2024
    risk 0.20cvss 3.0epss 0.00

    TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system…

  • CVE-2023-50311LowMar 31, 2024
    risk 0.20cvss 3.1epss 0.00

    IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 could disclose sensitive path information to an attacker that could reveal through debugging or error messages.

  • CVE-2022-0862LowMar 23, 2022
    risk 0.20cvss 3.1epss 0.01

    A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user's password. This…

  • CVE-2023-28857MedJun 27, 2023
    risk 0.19cvss 4.0epss 0.01

    Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When…

  • CVE-2021-45097LowDec 16, 2021
    risk 0.19cvss 2.9epss 0.00

    KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.

  • CVE-2018-17500LowMar 21, 2019
    risk 0.19cvss 2.9epss 0.00

    Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.

  • CVE-2025-62345LowMay 6, 2026
    risk 0.18cvss 2.7epss 0.00

    HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling implementation, increasing the risk of misconfiguration and operational errors.

  • CVE-2026-6408LowApr 22, 2026
    risk 0.18cvss 2.7epss 0.00

    Tanium addressed an information disclosure vulnerability in Tanium Server.

  • CVE-2026-27316LowApr 14, 2026
    risk 0.18cvss 2.7epss 0.00

    A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.

  • CVE-2025-67860LowFeb 25, 2026
    risk 0.18cvss 3.8epss 0.00

    A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.