CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. |
1Cisco 1Digital Network Architecture Center Jun 17, 2026 Jul 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencr...Show more |
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read...Show more |
1Biotronik 2Cardiomessenger Ii S Gsm Firmware Cardiomessenger Ii S T Line FirmwareJun 17, 2026 Jun 29, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for net...Show more |
2Apache Netapp3Activemq Artemis ArtemisOncommand Workflow AutomationJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executi...Show more |
1Bt Ctroms Terminal Project 1Bt Ctroms Terminal Jun 17, 2026 Jun 19, 2020 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is t...Show more |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials. |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jun 12, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an...Show more |
2Canonical Redhat2Openstack Cinder Ubuntu LinuxJun 17, 2026 Jun 10, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before...Show more |
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure. |
Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials. |
1Foxitsoftware 2Phantompdf ReaderNov 21, 2024 Jun 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action. |
An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action. |
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Of...Show more |
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure. |
system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive information (username and password) via any request, such as a password reset re...Show more |
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line. |
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users using HTML 'password fi...Show more |
2Signond Project Ubports2Signond Ubuntu TouchNov 21, 2024 May 7, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extensi...Show more |