CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2022-2739 MEDIUM
Red Hat Enterprise Linux 7 Extras Podman - Exposure of Sensitive Information via Environment Variables
CVSS 5.3
CVE-2022-2569 MEDIUM
Arcinformatique PCVue <= 12.0.27 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2022-2813 MEDIUM
SourceCodester Guest Management System - Info Disclosure
CVSS 4.3
CVE-2022-33928 MEDIUM
Dell Wyse Management Suite <3.6.1 - Info Disclosure
CVSS 6.4
CVE-2022-29090 HIGH
Dell Wyse Management Suite <3.6.1 - Info Disclosure
CVSS 8.5
CVE-2022-34924 HIGH
Landray Office Automation - Arbitrary File Read via custom.jsp
CVSS 7.5
CVE-2022-31205 HIGH
Omron CS/CJ/CP <2022-05-18 - Info Disclosure
CVSS 7.5
CVE-2022-30275 HIGH
Motorola MOSCAD Toolbox - Cleartext Storage of Sensitive Information in wmdlcdrv.ini
CVSS 7.5
CVE-2022-24660 HIGH
Goldshell ASIC Miners <2.2.1 - Info Disclosure
CVSS 7.5
CVE-2022-30626 MEDIUM
CHCNAV P5E GNSS Firmware - Cleartext Storage of Sensitive Information in WiFi AP Configuration
CVSS 6.3
CVE-2022-20219 MEDIUM
Android - Unencrypted User Directory Exposure via StorageManagerService Logic Error
CVSS 5.5
CVE-2022-22031 HIGH
Windows Credential Guard - Privilege Escalation
CVSS 7.8
CVE-2022-27549 MEDIUM
HCL Launch - Sensitive Information Disclosure via Plain Text Log Storage
CVSS 4.0
CVE-2022-22367 MEDIUM
IBM UrbanCode Deploy - Info Disclosure
CVSS 5.5
CVE-2022-22366 MEDIUM
IBM UrbanCode Deploy - Info Disclosure
CVSS 4.4
CVE-2022-22478 MEDIUM
IBM Spectrum Protect Client <8.1.14.0 - Info Disclosure
CVSS 5.5
CVE-2022-29620 MEDIUM
FileZilla 3.59.0 - Cleartext Storage of Sensitive Information in Memory
CVSS 6.5
CVE-2022-31004 HIGH
CVEProject/cve-services - Info Disclosure
CVSS 7.5
CVE-2022-23236 MEDIUM
NetApp E-Series SANtricity OS Controller 11.40-11.70.2 - Cleartext Storage of LDAP BIND Password
CVSS 4.4
CVE-2022-22484 MEDIUM
IBM Spectrum Protect Operations Center <8.1.12/13 - Info Disclosure
CVSS 5.5
CVE-2022-28214 HIGH
SAP BusinessObjects - Cleartext Storage of Sensitive Information in Sysmon Event Logs
CVSS 7.8
CVE-2022-29868 MEDIUM
1Password 7.2.4-7.9.x < 7.9.3 - Unauthenticated Sensitive Information Exposure via Process Validation Bypass
CVSS 5.5
CVE-2022-28162 LOW
Brocade SANnav < 2.2.0 - Cleartext Storage of Sensitive Information in REST API Authentication Token
CVSS 3.3
CVE-2022-0835 HIGH
AVEVA System Platform 2020 - Info Disclosure
CVSS 8.1
CVE-2022-25160 MEDIUM
Mitsubishielectric Fx5uc Firmware - Cleartext Storage
CVSS 5.9
Details
Vulnerabilities 818