CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2022-42284 MEDIUM
NVIDIA BMC < 00.19.07 - Cleartext Storage of Sensitive Information in Database
CVSS 6.2
CVE-2022-22470 MEDIUM
IBM Security Verify Governance 10.0 - Info Disclosure
CVSS 4.1
CVE-2022-45787 MEDIUM
Apache James < 0.8.9 - Cleartext Storage of Sensitive Information via Temporary File Permissions
CVSS 5.5
CVE-2022-41740 MEDIUM
IBM Robotic Process Automation <21.0.6 - Info Disclosure
CVSS 4.6
CVE-2022-37785 HIGH
WeCube Platform 3.2.2 - Cleartext Storage of Sensitive Information in Terminal Plugin Configuration
CVSS 7.5
CVE-2022-24120 MEDIUM
General Electric Renewable Energy <8.3.0 - Info Disclosure
CVSS 4.6
CVE-2022-22457 MEDIUM
IBM Security Verify Governance 10.0.1 - Cleartext Transmission of Sensitive Information
CVSS 5.3
CVE-2022-42931 LOW
Firefox < 106.0 - Cleartext Storage of Sensitive Information via Form Manager
CVSS 3.3
CVE-2022-47512 MEDIUM
SolarWinds Platform 2022.4 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2022-31697 MEDIUM
VMware vCenter Server - Cleartext Storage of Sensitive Information in Operation Logs
CVSS 5.5
CVE-2022-4312 MEDIUM
PcVue 8.10-15.2.3 - Unauthenticated Cleartext Credential Exposure in Email and SMS Configuration Files
CVSS 5.5
CVE-2022-35120 HIGH
IXPdata EasyInstall 6.6.14725 - Cleartext Storage of Sensitive Information
CVSS 8.8
CVE-2022-46155 HIGH
Airtable.js <0.11.6 - Info Disclosure
CVSS 7.6
CVE-2022-24188 HIGH
Ourphoto App 1.4.1 - Info Disclosure
CVSS 7.5
CVE-2022-29832 LOW
Mitsubishi Electric Corporation GX Works3 <1.015R - Info Disclosure
CVSS 3.7
CVE-2022-29826 MEDIUM
Mitsubishi Electric GX Works3 1.000A-1.087R - Unauthenticated Sensitive Information Disclosure via Cleartext Storage
CVSS 6.8
CVE-2022-25164 HIGH
Mitsubishi Electric GX Works3 <=1.095Z & MX OPC UA Configurator-R <=1.08J - Unauthenticated Info Exposure
CVSS 8.6
CVE-2022-45868 HIGH
H2 Database Engine < 2.2.220 - Cleartext Storage of Sensitive Information via CLI Argument
CVSS 8.4
CVE-2022-41933 MEDIUM
XWiki 13.1-13.10.8 - Plaintext Password Storage in Forgot Password Feature
CVSS 6.2
CVE-2022-2513 HIGH
Hitachi Energy PCM600 - Info Disclosure
CVSS 7.1
CVE-2022-43958 HIGH
QMS Automotive <V12.39 - Info Disclosure
CVSS 7.6
CVE-2022-42956 HIGH
PassWork 5.0.9 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2022-42955 HIGH
Passwork 5.0.9 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2022-38710 MEDIUM
IBM Robotic Process Automation <21.0.2 - Info Disclosure
CVSS 5.3
CVE-2022-35279 MEDIUM
IBM Business Automation Workflow Authenticated Sensitive Information Disclosure
CVSS 4.3
Details
Vulnerabilities 804