← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Postgresql
1Postgresql
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authenticati...Show more
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.Show less
1Abb
1Zenon
Jun 17, 2026
Aug 24, 2022
N/A· v4
8.4 HIGH· v3
N/A· v2
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering dat...Show more
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.Show less
1Abb
1Zenon
Jun 17, 2026
Aug 24, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
1Jenkins
1Collabnet
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller f...Show more
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.Show less
1Jenkins
1Git
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
1Fiserv
1Prologue
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would...Show more
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the configuration file. This would yield cleartext credentials for the database (to gain access to financial records of customers stored within the database), and in some cases would allow remote login to the database.Show less
1Redhat
1Keycloak
Jun 17, 2026
Aug 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threa...Show more
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.Show less
1Intel
2Active Management Technology Firmware
Standard Manageability
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
1Intel
2Active Management Technology Firmware
Standard Manageability
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.
1Intel
1Datacenter Group Event
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.
1Intel
1Team Blue
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
1Single Event Api
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
1Theforeman
1Foreman
Jun 17, 2026
Aug 16, 2022
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retr...Show more
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.Show less
1Emerson
1Openbsi
Jun 17, 2026
Aug 16, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user...Show more
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.Show less
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access t...Show more
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP. This issue may affect other AirVelocity and AirSpeed models.Show less
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
1Vmware
1Workstation
Jun 17, 2026
Aug 10, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the dis...Show more
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote server connected through VMware Workstation.Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Aug 10, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to exce...Show more
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server. Note: To successfully exploit this vulnerability, the attacker must have valid ERS administrative credentials.Show less
1Ibm
1Robotic Process Automation
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888.
1Hcltechsw
1Hcl Commerce
Jun 17, 2026
Jul 30, 2022
N/A· v4
5.0 MEDIUM· v3
N/A· v2
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.