CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536. |
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009 |
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These creden...Show more |
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The...Show more |
1Abb 2Irb140 Firmware Irc5 FirmwareJun 17, 2026 Jul 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of ou...Show more |
1Hp Application Lifecycle Management Quality Center Project 1Hp Application Lifecycle Management Quality Center Jun 17, 2026 Jul 2, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system. |
Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permis...Show more |
1Jenkins 1Github Coverage Reporter Jun 17, 2026 Jul 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read pe...Show more |
1Jenkins 1Testcomplete Support Jun 17, 2026 Jul 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master fil...Show more |
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. |
1Cisco 1Digital Network Architecture Center Jun 17, 2026 Jul 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencr...Show more |
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read...Show more |
1Biotronik 2Cardiomessenger Ii S Gsm Firmware Cardiomessenger Ii S T Line FirmwareJun 17, 2026 Jun 29, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for net...Show more |
2Apache Netapp3Activemq Artemis ArtemisOncommand Workflow AutomationJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executi...Show more |
1Bt Ctroms Terminal Project 1Bt Ctroms Terminal Jun 17, 2026 Jun 19, 2020 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is t...Show more |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials. |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jun 12, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an...Show more |
2Canonical Redhat2Openstack Cinder Ubuntu LinuxJun 17, 2026 Jun 10, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before...Show more |
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure. |