← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Jan 3, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.
2Citrix
Supermicro
5Netscaler Firmware
Netscaler Sd Wan FirmwareNetscaler Sdx Firmware+2 more
Nov 21, 2024
Jan 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards befo...Show more
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.Show less
1Redhat
1Quay
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.3 MEDIUM· v3
4.6 MEDIUM· v2
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored...Show more
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.Show less
1Ibm
1Watson Studio Local
Jun 17, 2026
Dec 30, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.
1Al Enterprise
2Omnivista 4760
Omnivista 8770
Jun 17, 2026
Dec 27, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session f...Show more
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP credentials encoded in a reversible format. Sessions are stored in /sessions/sess_<sessionid>.Show less
1Rakuten
1Rakuma
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created b...Show more
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created by the third party.Show less
1Zte
1Zxcloud Goldendata Vap
Jun 17, 2026
Dec 23, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.
1Arista
1Cloudvision Portal
Jun 17, 2026
Dec 19, 2019
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This onl...Show more
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable mode passwords which are different from the user's login password, OR 2. There are configlet builders that use the Device class and specify username and password explicitly Application logs are not accessible or visible from the CVP GUI. Application logs can only be read by authorized users with privileged access to the VM hosting the CVP application.Show less
1Dell
1Rsa Identity Governance And Lifecycle
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with...Show more
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.Show less
1Humaxdigital
1Hgb10r 02 Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
1Jenkins
1Weibo
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Redgate Sql Change Automation
Jun 17, 2026
Dec 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to th...Show more
Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Rundeck
Jun 17, 2026
Dec 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission,...Show more
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
2Redhat
Theforeman
2Hammer Cli
Satellite
Nov 21, 2024
Dec 13, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
1Openstack
1Keystone
Jun 17, 2026
Dec 9, 2019
N/A· v4
8.8 HIGH· v3
3.5 LOW· v2
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Us...Show more
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)Show less
1Weidmueller
40Ie Sw Pl08m 6tx 2sc Firmware
Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with...Show more
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with access to the device.Show less
1Weidmueller
40Ie Sw Pl08m 6tx 2sc Firmware
Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.
2Debian
Stanford
2Debian Linux
Webauth
Nov 21, 2024
Dec 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
webauth before 4.6.1 has authentication credential disclosure
1Fedoraproject
1389 Directory Server
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker...Show more
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.Show less
1Claws Mail
1Vcalendar
Nov 21, 2024
Nov 25, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Claws Mail vCalendar plugin: credentials exposed on interface