← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kmccontrols
1Bac A1616bc Firmware
Jun 17, 2026
Jan 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
1Trendmicro
1Password Manager
Jun 17, 2026
Jan 18, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious...Show more
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.Show less
2Apache
Oracle
8Commerce Guided Search
Communications Diameter Signaling RouterCommunications Element Manager+5 more
Jun 17, 2026
Jan 16, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the servi...Show more
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry. This case is not vulnerable. However it is also possible to obtain the keys from a JWK keystore file, by setting the configuration parameter "rs.security.keystore.type" to "jwk". For this case all keys are returned in this file "as is", including all private key and secret key credentials. This is an obvious security risk if the user has configured the signature keystore file with private or secret key credentials. From CXF 3.3.5 and 3.2.12, it is mandatory to specify an alias corresponding to the id of the key in the JWK file, and only this key is returned. In addition, any private key information is omitted by default. "oct" keys, which contain secret keys, are not returned at all.Show less
1Jenkins
1Redgate Sql Change Automation
Jun 17, 2026
Jan 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to t...Show more
Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.Show less
1Zohocorp
1Manageengine Eventlog Analyzer
Nov 21, 2024
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
1Granding
1Grand Ma300 Firmware
Nov 21, 2024
Jan 13, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Grand MA 300 allows a brute-force attack on the PIN.
1Arialsoftware
1Campaign Enterprise
Nov 21, 2024
Jan 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jan 10, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.
1Status2k
1Status2k
Nov 21, 2024
Jan 10, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Status2k does not remove the install directory allowing credential reset.
1Fortinet
1Fortisiem
Jun 17, 2026
Jan 7, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source co...Show more
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.Show less
1Anglers Net
1Cgi An Anlyzer
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 3, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.
2Citrix
Supermicro
5Netscaler Firmware
Netscaler Sd Wan FirmwareNetscaler Sdx Firmware+2 more
Nov 21, 2024
Jan 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards befo...Show more
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.Show less
1Redhat
1Quay
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.3 MEDIUM· v3
4.6 MEDIUM· v2
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored...Show more
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.Show less
1Ibm
1Watson Studio Local
Jun 17, 2026
Dec 30, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.
1Al Enterprise
2Omnivista 4760
Omnivista 8770
Jun 17, 2026
Dec 27, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session f...Show more
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP credentials encoded in a reversible format. Sessions are stored in /sessions/sess_<sessionid>.Show less
1Rakuten
1Rakuma
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created b...Show more
Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created by the third party.Show less
1Zte
1Zxcloud Goldendata Vap
Jun 17, 2026
Dec 23, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.
1Arista
1Cloudvision Portal
Jun 17, 2026
Dec 19, 2019
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This onl...Show more
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable mode passwords which are different from the user's login password, OR 2. There are configlet builders that use the Device class and specify username and password explicitly Application logs are not accessible or visible from the CVP GUI. Application logs can only be read by authorized users with privileged access to the VM hosting the CVP application.Show less
1Dell
1Rsa Identity Governance And Lifecycle
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with...Show more
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.Show less