CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2023-41964 MEDIUM
F5 BIG-IP 13.1.0-13.1.5 - Cleartext Storage of Sensitive Information in Database Variables
CVSS 4.3
CVE-2023-2809 HIGH
Sage 200 Spain <2023.38.001 - SQL Injection
CVSS 7.8
CVE-2023-4066 MEDIUM
Red Hat AMQ Broker - Info Disclosure
CVSS 5.5
CVE-2023-44159 HIGH
Acronis Cyber Protect 15 < 35979 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2023-44153 HIGH
Acronis Cyber Protect <35979 - Info Disclosure
CVSS 7.5
CVE-2023-41335 LOW
Synapse 1.66.0-1.93.0 - Cleartext Storage of Sensitive Information in Database
CVSS 3.7
CVE-2023-2358 MEDIUM
Hitachi Vantara Pentaho <9.5.0.0-9.3.0.4 - Info Disclosure
CVSS 4.3
CVE-2023-40715 MEDIUM
FortiTester <7.2.3 - Info Disclosure
CVSS 5.5
CVE-2023-4400 MEDIUM
Skyhigh Secure Web Gateway <11.2.14,10.2.25,12.2.1 - Info Disclosure
CVSS 6.2
CVE-2023-31069 CRITICAL
TSplus Remote Access <16.0.2.14 - Info Disclosure
CVSS 9.8
CVE-2023-3950 MEDIUM
GitLab 16.2-16.2.5, 16.3-16.3.1 - Unauthenticated Cleartext Storage of Sensitive Information in Google Cloud Logging
CVSS 5.5
CVE-2023-31925 MEDIUM
Brocade SANnav <2.3.0, <2.2.2a - Info Disclosure
CVSS 5.4
CVE-2023-31423 MEDIUM
Brocade SANnav <2.3.0-2.2.2a - Info Disclosure
CVSS 5.7
CVE-2023-3489 HIGH
Brocade Fabric OS v9.2.0 - Cleartext Storage of Sensitive Information in SupportSave File
CVSS 8.6
CVE-2023-4392 LOW
Control iD Gerencia Web <1.30 - Info Disclosure
CVSS 3.7
CVE-2023-40354 MEDIUM
MariaDB MaxScale < 2.5.28 - Cleartext Storage of Sensitive Information in Configuration File
CVSS 6.5
CVE-2023-31041 HIGH
Insyde InsydeH2O 5.0-5.5 - Cleartext Storage of Sensitive Information in SysPasswordDxe
CVSS 7.5
CVE-2023-39210 MEDIUM
Zoom Client SDK for Windows <5.15.0 - Info Disclosure
CVSS 5.5
CVE-2023-36136 MEDIUM
PHPJabbers Class Scheduling System 1.0 - Info Disclosure
CVSS 6.5
CVE-2023-39440 MEDIUM
SAP BusinessObjects Business Intelligence 420 - Cleartext Storage of Sensitive Information
CVSS 4.4
CVE-2023-39903 MEDIUM
Fujitsu Software Infrastructure Manager < 2.8.0.061 - Cleartext Sensitive Information Storage
CVSS 5.9
CVE-2023-33373 CRITICAL
Connected IO <2.1.0 - Info Disclosure
CVSS 9.8
CVE-2023-39379 HIGH
Fujitsu Software Infrastructure Manager 2.8.0.060 - Cleartext Storage of Sensitive Information in Maintenance Data
CVSS 7.5
CVE-2023-30146 HIGH
Assmann HT-IP211HDP Firmware 2.000.022 - Unauthenticated Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2023-39144 HIGH
Element55 KnowMore <21 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 804