CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2022-31405 MEDIUM
MV iDigital Clinic Enterprise (iDCE) 1.0 - Info Disclosure
CVSS 6.5
CVE-2022-34351 MEDIUM
IBM QRadar SIEM 7.4-7.5 - Unauthorized Information Exposure via Domain Security Profile
CVSS 5.9
CVE-2022-41734 MEDIUM
IBM Maximo Asset Management <7.6.1.3 - Info Disclosure
CVSS 5.3
CVE-2022-45154 MEDIUM
supportutils < 3.0.10-95.51.1 - Cleartext Storage of Sensitive Information in Support Logs
CVSS 4.4
CVE-2022-3089 MEDIUM
Echelon SmartServer 2.2 - Info Disclosure
CVSS 6.3
CVE-2022-34388 HIGH
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Cleartext Sensitive Data Storage
CVSS 7.1
CVE-2022-24410 MEDIUM
Dell Alienware BIOS < 1.15.1 - Unauthenticated Sensitive Information Exposure via Debug Interfaces
CVSS 6.8
CVE-2022-43757 CRITICAL
SUSE Rancher <2.5.17, <2.6.10, <2.7.1 - Info Disclosure
CVSS 9.9
CVE-2022-45098 MEDIUM
Dell PowerScale OneFS 9.1.0.0-9.1.0.25 - Authenticated Sensitive Information Disclosure in S3 Component
CVSS 6.1
CVE-2022-45897 MEDIUM
Xerox WorkCentre 3550 25.003.03.000 - Authenticated Cleartext Storage of Sensitive Information in SMB Server Settings
CVSS 6.5
CVE-2022-48073 HIGH
Phicomm K2G v22.6.3.20 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2022-48071 HIGH
Phicomm K2 v22.6.534.263 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2022-38112 HIGH
SolarWinds Database Performance Analyzer < 2022.4 - Cleartext Storage of Sensitive Information in Heap Memory Dumps
CVSS 7.5
CVE-2022-45439 MEDIUM
Zyxel AX7501-B0 Firmware < 5.17(ABPC.3)C0 - Cleartext Storage of Sensitive WiFi Credentials
CVSS 6.5
CVE-2022-42284 MEDIUM
NVIDIA BMC < 00.19.07 - Cleartext Storage of Sensitive Information in Database
CVSS 6.2
CVE-2022-22470 MEDIUM
IBM Security Verify Governance 10.0 - Info Disclosure
CVSS 4.1
CVE-2022-45787 MEDIUM
Apache James < 0.8.9 - Cleartext Storage of Sensitive Information via Temporary File Permissions
CVSS 5.5
CVE-2022-41740 MEDIUM
IBM Robotic Process Automation <21.0.6 - Info Disclosure
CVSS 4.6
CVE-2022-37785 HIGH
WeCube Platform 3.2.2 - Cleartext Storage of Sensitive Information in Terminal Plugin Configuration
CVSS 7.5
CVE-2022-24120 MEDIUM
General Electric Renewable Energy <8.3.0 - Info Disclosure
CVSS 4.6
CVE-2022-22457 MEDIUM
IBM Security Verify Governance 10.0.1 - Cleartext Transmission of Sensitive Information
CVSS 5.3
CVE-2022-42931 LOW
Firefox < 106.0 - Cleartext Storage of Sensitive Information via Form Manager
CVSS 3.3
CVE-2022-47512 MEDIUM
SolarWinds Platform 2022.4 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2022-31697 MEDIUM
VMware vCenter Server - Cleartext Storage of Sensitive Information in Operation Logs
CVSS 5.5
CVE-2022-4312 MEDIUM
PcVue 8.10-15.2.3 - Unauthenticated Cleartext Credential Exposure in Email and SMS Configuration Files
CVSS 5.5
Details
Vulnerabilities 818