CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

805 vulnerabilities with CWE-312
CVE-2020-12859 MEDIUM
COVIDSafe <v1.0.17 - Info Disclosure
CVSS 5.3
CVE-2020-10706 MEDIUM
OpenShift Container Platform - Info Disclosure
CVSS 6.3
CVE-2020-11415 MEDIUM
Sonatype Nexus Repository Manager 2.0-2.14.16 - Cleartext Storage of Sensitive LDAP Credentials
CVSS 4.9
CVE-2020-2177 MEDIUM
Jenkins Copr Plugin < 0.3 - Cleartext Storage of Sensitive Information in Job Config Files
CVSS 4.3
CVE-2020-11826 HIGH
Memono 3.8 - Cleartext Storage of Sensitive Information in Database
CVSS 7.5
CVE-2020-11694 HIGH
JetBrains PyCharm 2019.2.5 and 2019.3 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2020-10267 HIGH
Universal Robots ur_software 3.0.14989-3.1.18213 - Cleartext Storage of Sensitive Information in URCaps Files
CVSS 7.5
CVE-2020-5723 CRITICAL
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
CVSS 9.8
CVE-2020-3921 HIGH
UltraLog Express Firmware - Cleartext Storage of Sensitive Information
CVSS 8.6
CVE-2020-6980 LOW
Rockwell Automation MicroLogix 1400/1100 & RSLogix 500 <12.001 Cleartext SMTP Credentials
CVSS 3.3
CVE-2020-10532 HIGH
WatchGuard Fireware <5.8.5.10317 - Info Disclosure
CVSS 7.5
CVE-2020-2154 MEDIUM
Jenkins Zephyr for JIRA Test Management Plugin < 1.5 - Cleartext Storage of Sensitive Information
CVSS 5.5
CVE-2020-6794 MEDIUM
Thunderbird <68.5 - Info Disclosure
CVSS 6.5
CVE-2020-9407 MEDIUM
IBL Online Weather < 4.3.5 - Sensitive Information Exposure via IWEBSERVICE_JSONRPC_COOKIE
CVSS 5.3
CVE-2020-3935 HIGH
TAIWAN SECOM CO., LTD. - Info Disclosure
CVSS 7.5
CVE-2020-4224 MEDIUM
IBM StoredIQ 7.6.0.17-7.6.0.20 - Sensitive Information Disclosure via Unencrypted Symbolic Links
CVSS 5.5
CVE-2020-7213 HIGH
Parallels 13 - Cleartext Storage of Sensitive Information via HTTP Update Process
CVSS 7.5
CVE-2019-25279 HIGH
FaceSentry Access Control System 6.4.8 - Info Disclosure
CVSS 7.5
CVE-2019-16638 HIGH
Ruijie EG-2000SE EG_RGOS 11.1(1)B1 - Cleartext Storage of Sensitive Information in Config File
CVSS 7.5
CVE-2019-18630 HIGH
Xerox AltaLink B80xx/C80xx Firmware < 101.00x.099.28200 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2019-4687 MEDIUM
IBM Security Guardium Data Encryption (GDE) <3.0.0.2 - Info Disclosure
CVSS 5.3
CVE-2019-4738 MEDIUM
IBM Sterling B2B Integrator Standard Edition <6.0.3.1 - Info Disclo...
CVSS 6.5
CVE-2019-4676 HIGH
IBM Security Identity Manager Virtual Appliance 7.0.2 - Info Disclo...
CVSS 7.8
CVE-2019-18254 MEDIUM
BIOTRONIK CardioMessenger II-S GSM and T-Line Firmware - Cleartext Storage of Sensitive Information
CVSS 4.6
CVE-2019-17655 MEDIUM
FortiOS < 6.2.3 - Cleartext Storage of Sensitive Information in SSL VPN Session Files
CVSS 5.3
Details
Vulnerabilities 805