CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2022-35120 HIGH
IXPdata EasyInstall 6.6.14725 - Cleartext Storage of Sensitive Information
CVSS 8.8
CVE-2022-46155 HIGH
Airtable.js <0.11.6 - Info Disclosure
CVSS 7.6
CVE-2022-24188 HIGH
Ourphoto App 1.4.1 - Info Disclosure
CVSS 7.5
CVE-2022-29832 LOW
Mitsubishi Electric Corporation GX Works3 <1.015R - Info Disclosure
CVSS 3.7
CVE-2022-29826 MEDIUM
Mitsubishi Electric GX Works3 1.000A-1.087R - Unauthenticated Sensitive Information Disclosure via Cleartext Storage
CVSS 6.8
CVE-2022-25164 HIGH
Mitsubishi Electric GX Works3 <=1.095Z & MX OPC UA Configurator-R <=1.08J - Unauthenticated Info Exposure
CVSS 8.6
CVE-2022-45868 HIGH
H2 Database Engine < 2.2.220 - Cleartext Storage of Sensitive Information via CLI Argument
CVSS 8.4
CVE-2022-41933 MEDIUM
XWiki 13.1-13.10.8 - Plaintext Password Storage in Forgot Password Feature
CVSS 6.2
CVE-2022-2513 HIGH
Hitachi Energy PCM600 - Info Disclosure
CVSS 7.1
CVE-2022-43958 HIGH
QMS Automotive <V12.39 - Info Disclosure
CVSS 7.6
CVE-2022-42956 HIGH
PassWork 5.0.9 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2022-42955 HIGH
Passwork 5.0.9 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2022-38710 MEDIUM
IBM Robotic Process Automation <21.0.2 - Info Disclosure
CVSS 5.3
CVE-2022-35279 MEDIUM
IBM Business Automation Workflow Authenticated Sensitive Information Disclosure
CVSS 4.3
CVE-2022-34339 MEDIUM
IBM Cognos Analytics 11.1.0-11.1.7 - Authenticated Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2022-39364 MEDIUM
Nextcloud Server <23.0.9 & Enterprise <22.2.10.5 - Cleartext SharePoint Credentials in Logs
CVSS 4.0
CVE-2022-39351 MEDIUM
OWASP Dependency-Track < 4.6.0 - Cleartext Storage of Sensitive Information in Audit Log
CVSS 4.4
CVE-2022-2805 MEDIUM
Red Hat Virtualization - Cleartext Storage of Sensitive Information in Log Files
CVSS 6.5
CVE-2022-3540 MEDIUM
hunter2 < 2.1.0 - Authenticated Cleartext Storage of Sensitive Information via Auto-Completion Input
CVSS 6.5
CVE-2022-33918 MEDIUM
Dell GeoDrive <2.2 - Info Disclosure
CVSS 5.5
CVE-2022-32217 MEDIUM
Rocket.Chat < 4.6.4 - Sensitive Information Exposure via OAuth Token Logging
CVSS 5.3
CVE-2022-41248 MEDIUM
Jenkins BigPanda Notifier Plugin <1.4.0 - Info Disclosure
CVSS 5.3
CVE-2022-26390 MEDIUM
Baxter Spectrum WBM - Info Disclosure
CVSS 4.2
CVE-2022-37857 HIGH
hauk 1.6.1 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2022-22069 HIGH
Qualcomm AQT1000 and Multiple Snapdragon Firmware - Cleartext Storage of Sensitive Information
CVSS 7.7
Details
Vulnerabilities 818