CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2020-4980 MEDIUM
IBM QRadar SIEM 7.3-7.4 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2020-12731 HIGH
MagicMotion Flamingo 2 - Info Disclosure
CVSS 7.5
CVE-2020-15384 MEDIUM
Brocade SANNav <2.1.1 - Info Disclosure
CVSS 5.3
CVE-2020-29324 HIGH
DLink Router DIR-895L MFC <v1.21b05 - Info Disclosure
CVSS 7.5
CVE-2020-22783 MEDIUM
Etherpad < 1.8.3 - Cleartext Storage of Sensitive Information in Database and Log Files
CVSS 6.5
CVE-2020-11924 MEDIUM
WiZ Colors A60 1.14.0 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2020-11923 MEDIUM
WiZ Colors A60 1.14.0 - Cleartext Storage of Sensitive API Credentials
CVSS 5.5
CVE-2020-4944 MEDIUM
IBM UrbanCode Deploy Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2020-4884 MEDIUM
IBM UrbanCode Deploy 6.2.7.9, 7.0.5.4, and 7.1.1.1 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2020-35455 HIGH
Taidii Diibear 2.4.0 - Cleartext Storage of Sensitive Information in Shared Preferences and SQLite Database
CVSS 7.8
CVE-2020-35454 MEDIUM
Taidii Diibear 2.4.0 - Cleartext Storage of Sensitive Information in Android Backup
CVSS 6.8
CVE-2020-36248 LOW
owncloud_client < 2.15 - Unauthenticated PIN Lock Bypass via ADB Backup Restore
CVSS 3.9
CVE-2020-4189 MEDIUM
IBM Security Guardium 11.2 - Sensitive Information Exposure via Response Headers
CVSS 4.3
CVE-2020-29001 HIGH
Geeni and Merkury Camera/Doorbell Firmware - Cleartext Storage of Sensitive Credentials in RESTful API
CVSS 7.2
CVE-2020-4604 MEDIUM
IBM Security Guardium Insights 2.0.2 - Cleartext Storage of Sensitive Information
CVSS 4.4
CVE-2020-5018 HIGH
IBM Spectrum Protect Plus 10.1.0-10.1.6 - Cleartext Storage of Sensitive Information in URLs
CVSS 7.5
CVE-2020-25678 MEDIUM
Ceph < 16.2.0 - Cleartext Storage of Sensitive Information in Mgr Module Logs
CVSS 4.4
CVE-2020-5805 HIGH
Marvell QConvergeConsole GUI <= 5.5.0.74 - Info Disclosure
CVSS 8.8
CVE-2020-24577 HIGH
D-Link DSL-2888A <AU_2.31_V1.1.47ae55 - Info Disclosure
CVSS 7.5
CVE-2020-29502 HIGH
Dell EMC PowerStore <1.0.3.0.5.007 - Info Disclosure
CVSS 7.5
CVE-2020-29501 MEDIUM
Dell EMC PowerStore <1.0.3.0.5.007 - Info Disclosure
CVSS 6.4
CVE-2020-29500 HIGH
Dell EMC PowerStore <1.0.3.0.5.007 - Info Disclosure
CVSS 7.5
CVE-2020-29489 MEDIUM
Dell EMC Unity <5.0.4.0.5.012 - Info Disclosure
CVSS 6.4
CVE-2020-23249 MEDIUM
GigaVUE-OS 5.4-5.9 - Info Disclosure
CVSS 4.7
CVE-2020-26288 HIGH
Parse Server <4.5.0 - Info Disclosure
CVSS 7.7
Details
Vulnerabilities 818