CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2022-22366 MEDIUM
IBM UrbanCode Deploy - Info Disclosure
CVSS 4.4
CVE-2022-22478 MEDIUM
IBM Spectrum Protect Client <8.1.14.0 - Info Disclosure
CVSS 5.5
CVE-2022-29620 MEDIUM
FileZilla 3.59.0 - Cleartext Storage of Sensitive Information in Memory
CVSS 6.5
CVE-2022-31004 HIGH
CVEProject/cve-services - Info Disclosure
CVSS 7.5
CVE-2022-23236 MEDIUM
NetApp E-Series SANtricity OS Controller 11.40-11.70.2 - Cleartext Storage of LDAP BIND Password
CVSS 4.4
CVE-2022-22484 MEDIUM
IBM Spectrum Protect Operations Center <8.1.12/13 - Info Disclosure
CVSS 5.5
CVE-2022-28214 HIGH
SAP BusinessObjects - Cleartext Storage of Sensitive Information in Sysmon Event Logs
CVSS 7.8
CVE-2022-29868 MEDIUM
1Password 7.2.4-7.9.x < 7.9.3 - Unauthenticated Sensitive Information Exposure via Process Validation Bypass
CVSS 5.5
CVE-2022-28162 LOW
Brocade SANnav < 2.2.0 - Cleartext Storage of Sensitive Information in REST API Authentication Token
CVSS 3.3
CVE-2022-0835 HIGH
AVEVA System Platform 2020 - Info Disclosure
CVSS 8.1
CVE-2022-25160 MEDIUM
Mitsubishielectric Fx5uc Firmware - Cleartext Storage
CVSS 5.9
CVE-2022-25158 CRITICAL
Mitsubishielectric Fx5uc Firmware - Cleartext Storage
CVSS 9.1
CVE-2022-26148 CRITICAL
Grafana & Zabbix Integration - Credentials Disclosure
CVSS 9.8
CVE-2022-23234 MEDIUM
NetApp SnapCenter < 4.5 - Authenticated Plaintext Credential Exposure
CVSS 5.5
CVE-2022-26778 MEDIUM
Veritas System Recovery <21 - Info Disclosure
CVSS 5.3
CVE-2022-21818 MEDIUM
NVIDIA License System < 1.1 - Cleartext Storage of Sensitive Information
CVSS 5.4
CVE-2022-22789 MEDIUM
Charactell FormStorm - Unauthenticated Account Takeover via Password File Manipulation
CVSS 6.1
CVE-2022-23129 MEDIUM
Iconics Genesis64 < 10.97 - Cleartext Storage
CVSS 5.5
CVE-2022-20660 MEDIUM
Cisco IP Phone Firmware < 14.1(1) - Unauthenticated Cleartext Storage of Sensitive Information
CVSS 4.6
CVE-2021-22509 HIGH
NetIQ Advance Auth <6.3.5.1 - Info Disclosure
CVSS 8.1
CVE-2021-39077 MEDIUM
IBM Security Guardium 10.5-11.4 - Cleartext Transmission of Sensitive Information
CVSS 4.4
CVE-2021-36782 CRITICAL
SUSE Rancher < 2.5.16 - Authenticated Cleartext Storage of Sensitive Information via Kubernetes API
CVSS 9.9
CVE-2021-39009 MEDIUM
IBM Cognos Analytics <11.2.1 - Info Disclosure
CVSS 5.5
CVE-2021-3585 MEDIUM
openstack-tripleo-heat-templates - Info Disclosure
CVSS 5.5
CVE-2021-41639 MEDIUM
MELAG FTP Server 2.2.0.4 - Cleartext Storage of Sensitive Information
CVSS 5.5
Details
Vulnerabilities 804