CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure. |
2Citrix Supermicro5Netscaler Firmware Netscaler Sd Wan FirmwareNetscaler Sdx Firmware+2 moreNov 21, 2024 Jan 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards befo...Show more |
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored...Show more |
IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413. |
1Al Enterprise 2Omnivista 4760 Omnivista 8770Jun 17, 2026 Dec 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session f...Show more |
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created b...Show more |
1Zte 1Zxcloud Goldendata Vap Jun 17, 2026 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access. |
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This onl...Show more |
1Dell 1Rsa Identity Governance And Lifecycle Jun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with...Show more |
1Humaxdigital 1Hgb10r 02 Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP. |
Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. |
1Jenkins 1Redgate Sql Change Automation Jun 17, 2026 Dec 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to th...Show more |
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission,...Show more |
2Redhat Theforeman2Hammer Cli SatelliteNov 21, 2024 Dec 13, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable |
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Us...Show more |
1Weidmueller 40Ie Sw Pl08m 6tx 2sc Firmware Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 moreJun 17, 2026 Dec 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with...Show more |
1Weidmueller 40Ie Sw Pl08m 6tx 2sc Firmware Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 moreJun 17, 2026 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext. |
2Debian Stanford2Debian Linux WebauthNov 21, 2024 Dec 3, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 webauth before 4.6.1 has authentication credential disclosure |
1Fedoraproject 1389 Directory Server Jun 17, 2026 Nov 25, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker...Show more |
Claws Mail vCalendar plugin: credentials exposed on interface |