CWE-312
812 CVEs • Abstraction: Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CVEs (812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys. |
1Yokogawa 8B/m9000 Vp B/m9000csCentum Cs 1000+5 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers th...Show more |
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD D...Show more |
A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/Fcms/View/system_log.html. The manipulation leads to information disclo...Show more |
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The...Show more |
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have v...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Mar 22, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve in...Show more |
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4 and 6.4.0 through 6.4.10 may allow a remote authenticated attacker...Show more |
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90. |
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS...Show more |
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve th...Show more |
1Mv Idigital Clinic Enterprise Project 1Mv Idigital Clinic Enterprise Jun 17, 2026 Feb 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Feb 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402. |
1Ibm 2Maximo Application Suite Maximo Asset ManagementJun 17, 2026 Feb 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Feb 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463. |
A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the...Show more |
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, t...Show more |
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsJun 17, 2026 Feb 11, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exp...Show more |
1Dell 157Alienware 13 R2 Firmware Alienware 13 R3 FirmwareAlienware 15 R2 Firmware+154 moreJun 17, 2026 Feb 10, 2023 N/A· v4 4.2 MEDIUM· v3 N/A· v2 Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to re...Show more |
HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotatio...Show more |