CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Kmccontrols 1Bac A1616bc Firmware Jun 17, 2026 Jan 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file. |
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious...Show more |
2Apache Oracle8Commerce Guided Search Communications Diameter Signaling RouterCommunications Element Manager+5 moreJun 17, 2026 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the servi...Show more |
1Jenkins 1Redgate Sql Change Automation Jun 17, 2026 Jan 15, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to t...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. |
1Granding 1Grand Ma300 Firmware Nov 21, 2024 Jan 13, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Grand MA 300 allows a brute-force attack on the PIN. |
1Arialsoftware 1Campaign Enterprise Nov 21, 2024 Jan 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Jan 10, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429. |
Status2k does not remove the install directory allowing credential reset. |
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source co...Show more |
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer. |
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure. |
2Citrix Supermicro5Netscaler Firmware Netscaler Sd Wan FirmwareNetscaler Sdx Firmware+2 moreNov 21, 2024 Jan 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards befo...Show more |
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored...Show more |
IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413. |
1Al Enterprise 2Omnivista 4760 Omnivista 8770Jun 17, 2026 Dec 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session f...Show more |
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created b...Show more |
1Zte 1Zxcloud Goldendata Vap Jun 17, 2026 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access. |
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This onl...Show more |
1Dell 1Rsa Identity Governance And Lifecycle Jun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with...Show more |