← Back
CWE-522

1,466 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dropbox
1Dropbox
Jun 17, 2026
Jul 8, 2019
N/A· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed i...Show more
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.Show less
1Fortinet
1Fcm Mb40 Firmware
Jun 17, 2026
Jul 8, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fi...Show more
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files....Show more
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configured to synchronize IDE settings using a public repository, these credentials were published to this repository. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has bee...Show more
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.Show less
1Jetbrains
1Hub
Jun 17, 2026
Jul 3, 2019
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the aud...Show more
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.Show less
1Calamares
1Calamares
Jun 17, 2026
Jul 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this o...Show more
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.Show less
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
1Nortekcontrol
2Linear Emerge 5000p Firmware
Linear Emerge 50p Firmware
Jun 17, 2026
Jul 1, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
1Logitech
1R500 Firmware
Jun 17, 2026
Jun 29, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters...Show more
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.Show less
2Debian
Vmware
2Debian Linux
Spring Security
Jun 17, 2026
Jun 26, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging Plain...Show more
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".Show less
1Ibm
1Spectrum Protect Plus
Jun 17, 2026
Jun 19, 2019
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 16217...Show more
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.Show less
1Cloud Foundry
1Bosh
Jun 17, 2026
Jun 19, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credential...Show more
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.Show less
1Ibm
1Cloud Private
Jun 17, 2026
Jun 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
2Open Cloud Integrity Tehnology
Openattestation
Jun 17, 2026
Jun 13, 2019
N/A· v4
3.6 LOW· v3
3.3 LOW· v2
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.