← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Vmware
2Debian Linux
Spring Security
Jun 17, 2026
Jun 26, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging Plain...Show more
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".Show less
1Ibm
1Spectrum Protect Plus
Jun 17, 2026
Jun 19, 2019
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 16217...Show more
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.Show less
1Cloud Foundry
1Bosh
Jun 17, 2026
Jun 19, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credential...Show more
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.Show less
1Ibm
1Cloud Private
Jun 17, 2026
Jun 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
3.6 LOW· v3
3.3 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Fujielectric
1V Server
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database...Show more
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.Show less
1Siemens
4Scalance X 200 Firmware
Scalance X 200irt FirmwareScalance X 300 Firmware+1 more
Jun 17, 2026
Jun 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300...Show more
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X-414-3E (All versions). The affected devices store passwords in a recoverable format. An attacker may extract and recover device passwords from the device configuration. Successful exploitation requires access to a device configuration backup and impacts confidentiality of the stored passwords.Show less
7Canonical
DebianFedoraproject+4 more
14Cloud Backup
Converged Systems Advisor AgentDebian Linux+11 more
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attack...Show more
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.Show less
1Kyocera
1Command Center Rx
Jun 17, 2026
Jun 6, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a cleartext FTP or SMB password.
1Auo
1Solar Data Recorder
Jun 17, 2026
Jun 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password,...Show more
An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.Show less
1Carel
1Pcoweb Card Firmware
Jun 17, 2026
Jun 3, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.
1Schneider Electric
2Citectscada
Scada Expert Vijeo Citect
Jun 17, 2026
May 31, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials.
1Eficode
1Influxdb
Jun 17, 2026
May 31, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Traefik
1Traefik
Jun 17, 2026
May 29, 2019
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficient access control (which is contrary to the API documentation), allows...Show more
types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficient access control (which is contrary to the API documentation), allows remote authenticated users to discover password hashes by reading the Basic HTTP Authentication or Digest HTTP Authentication section, or discover a key by reading the ClientTLS section. These can be found in the JSON response to a /api request.Show less