← Back
CWE-312

812 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Xclarity Controller
Jun 17, 2026
Apr 13, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is...Show more
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore password typically exists in this internal log buffer for less than 10 minutes before being overwritten. Generating an FFDC service log will include the log buffer contents, including the backup/restore password if present. The FFDC service log is only generated when requested by a privileged XCC user and it is only accessible to the privileged XCC user that requested the file. The backup/restore password is not captured if the backup/restore is initiated directly from XCC.Show less
1Teradici
1Pcoip Connection Manager And Security Gateway
Jun 17, 2026
Apr 6, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3.
1Wizconnected
1Colors A60 Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device.
1Wizconnected
1Wiz
Jun 17, 2026
Apr 2, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.
1Ibm
1Urbancode Deploy
Jun 17, 2026
Mar 30, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 19194...Show more
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.Show less
1Ibm
1Urbancode Deploy
Jun 17, 2026
Mar 30, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
1Acexy
1Wireless N Wifi Repeater Firmware
Jul 9, 2026
Mar 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 26, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In all versions of GitLab, marshalled session keys were being stored in Redis.
1Typo3
1Typo3
Jun 17, 2026
Mar 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of addition...Show more
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. This is fixed in versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.Show less
1Taidii
1Diibear
Jun 17, 2026
Mar 17, 2021
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.
1Taidii
1Diibear
Jun 17, 2026
Mar 17, 2021
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.
1Xerox
10Altalink B8045 Firmware
Altalink B8055 FirmwareAltalink B8065 Firmware+7 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypte...Show more
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.Show less
1Rangerstudio
1Directus
Jun 17, 2026
Feb 23, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called autom...Show more
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Keybase
1Keybase
Jun 17, 2026
Feb 23, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails...Show more
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.Show less
1Genymobile
1Genymotion Desktop
Jun 17, 2026
Feb 22, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device scre...Show more
Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screenShow less
1Owncloud
1Owncloud Client
Jun 17, 2026
Feb 19, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
1Mutare
1Voice
Jun 17, 2026
Feb 16, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password information for external systems is visible in cleartext. The Settings.asp page is affected by this iss...Show more
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password information for external systems is visible in cleartext. The Settings.asp page is affected by this issue.Show less
1Tp Link
1Archer C5v Firmware
Jun 17, 2026
Feb 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.
1Ibm
1Security Verify Information Queue
Jun 17, 2026
Feb 12, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.
1Ibm
1Security Verify Information Queue
Jun 17, 2026
Feb 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185.