CWE-759
21 CVEs • Abstraction: Variant
Use of a One-Way Hash without a Salt
The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ge 1Asset Performance Management Classic Jun 17, 2026 Sep 23, 2020 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform a...Show more |