CWE-312
812 CVEs • Abstraction: Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CVEs (812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant...Show more |
1Hitachivantara 1Pentaho Business Analytics Jun 17, 2026 Sep 27, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext.
|
A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configur...Show more |
1Skyhighsecurity 1Secure Web Gateway Jun 17, 2026 Sep 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information s...Show more |
1Tsplus 2Tsplus Remote Access Tsplus Remote WorkJun 17, 2026 Sep 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. |
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming de...Show more |
Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be...Show more |
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the loc...Show more |
The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fa...Show more |
1Assaabloy 1Control Id Gerencia Web Jun 17, 2026 Aug 17, 2023 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie Handler. The manipulation leads to cleartext storage o...Show more |
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /...Show more |
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure. |
1Zoom 1Meeting Software Development Kit Jun 17, 2026 Aug 8, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access. |
1Phpjabbers 1Class Scheduling System Jun 17, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text. |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 8, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to ge...Show more |
1Fujitsu 1Software Infrastructure Manager Jun 17, 2026 Aug 7, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in this specific case at /var/log/fujitsu/ServerViewSuite/ism/FirmwareManagement/FirmwareManagement.log) a...Show more |
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices. |
1Fujitsu 1Software Infrastructure Manager Jun 17, 2026 Aug 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be re...Show more |
Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials. |
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext. |