← Back
CWE-312

812 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Couchbase
1Couchbase Server
Jun 17, 2026
Nov 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This i...Show more
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.Show less
1Ibm
6Engineering Lifecycle Optimization
Engineering Workflow ManagementRational Collaborative Lifecycle Management+3 more
Jun 17, 2026
Oct 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
1Onepeloton
1Peloton
Jun 17, 2026
Oct 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket...Show more
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application.Show less
1Ibm
1Security Risk Manager On Cp4s
Jun 17, 2026
Oct 19, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.
1Microsoft
11365 Apps
OfficeWindows 10+8 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Rich Text Edit Control Information Disclosure Vulnerability
1Ibm
1Data Risk Manager
Jun 17, 2026
Oct 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
1Ecoa
3Ecs Router Controller Ecs Firmware
Riskbuster FirmwareRiskterminator
Jun 17, 2026
Sep 30, 2021
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
1Riconmobile
1S9922l Firmware
Jun 17, 2026
Sep 28, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
1Ibm
1Jazz For Service Management
Jun 17, 2026
Sep 23, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
1Sap
1Business Client
Jun 17, 2026
Sep 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive...Show more
When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials. This would allow the attacker to compromise the corresponding backend for which the credentials are valid.Show less
1Siemens
2Simatic Cp 1543 1 Firmware
Simatic Cp 1545 1 Firmware
Jun 17, 2026
Sep 14, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1.1). An attacker with access to the subnet of the affected device could retrieve...Show more
A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1.1). An attacker with access to the subnet of the affected device could retrieve sensitive information stored in cleartext.Show less
1Autumn Project
1Autumn
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".
1Hitachiabb Powergrids
1Sdm600 Firmware
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Da...Show more
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.0 MEDIUM· v3
4.3 MEDIUM· v2
An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.
1Otrs
1Otrs
Jun 17, 2026
Sep 6, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version...Show more
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.Show less
1Brave
1Brave
Jun 17, 2026
Aug 31, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
1Axis
1Device Manager
Jun 17, 2026
Aug 25, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentia...Show more
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.Show less
1Primekey
1Ejbca
Jun 17, 2026
Aug 25, 2021
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext...Show more
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Aug 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker may be able to recover plaint...Show more
A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker may be able to recover plaintext contents of an S/MIME-encrypted e-mail.Show less
1Octopus
1Octopus Server
Jun 17, 2026
Aug 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.