CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

884 vulnerabilities with CWE-319
CVE-2019-4280 MEDIUM
IBM Sterling File Gateway <6.0.1.0 - Info Disclosure
CVSS 5.3
CVE-2019-16924 HIGH
Nulock 1.5.0 - Cleartext Transmission of Sensitive Information via Bluetooth
CVSS 8.8
CVE-2019-11739 MEDIUM
Thunderbird <68.1-<60.9 - Info Disclosure
CVSS 6.5
CVE-2019-6652 MEDIUM
F5 BIG-IQ Centralized Management 6.0.0-6.1.0 - Unauthenticated Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2019-10428 HIGH
Jenkins Aqua Security Scanner Plugin <= 3.0.17 - Cleartext Transmission of Sensitive Credentials
CVSS 7.5
CVE-2019-10427 MEDIUM
Jenkins Aqua MicroScanner < 1.0.7 - Cleartext Transmission of Sensitive Credentials
CVSS 5.3
CVE-2019-10412 HIGH
Jenkins Inedo ProGet Plugin < 1.2 - Cleartext Transmission of Sensitive Information
CVSS 7.5
CVE-2019-10411 HIGH
Jenkins Inedo BuildMaster Plugin < 2.4.0 - Cleartext Transmission of Sensitive Credentials
CVSS 7.5
CVE-2019-5505 CRITICAL
ONTAP Select Deploy Administration Utility 2.2-2.12.1 - Cleartext Transmission of Sensitive Information
CVSS 9.8
CVE-2019-15635 MEDIUM
Grafana 5.4.0 - Cleartext Transmission of Sensitive Information via Data Source Settings
CVSS 4.9
CVE-2019-10397 LOW
Jenkins Aqua Security Serverless Scanner < 1.0.4 - Cleartext Transmission of Sensitive Information
CVSS 3.1
CVE-2019-5503 MEDIUM
NetApp OnCommand Workflow Automation - Cleartext Transmission of Sensitive Information
CVSS 5.3
CVE-2019-14319 MEDIUM
TikTok 12.2.0 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2019-10391 MEDIUM
Jenkins IBM Application Security on Cloud Plugin < 1.2.4 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2019-5635 HIGH
Hickory Smart Ethernet Bridge - Cleartext Transmission of Sensitive Information via MQTT
CVSS 7.5
CVE-2019-11276 MEDIUM
Pivotal Application Service 2.3.0-2.3.15 - Cleartext Transmission of Sensitive Information via Spring Actuator
CVSS 5.4
CVE-2019-15135 HIGH
OMG DDS Security 1.1 - Cleartext Transmission of Sensitive Information via Handshake Protocol
CVSS 7.5
CVE-2019-0348 MEDIUM
SAP BusinessObjects Business Intelligence Platform 4.1-4.2 - Cleartext Transmission of Sensitive Database Information
CVSS 6.5
CVE-2019-0346 MEDIUM
SAP BusinessObjects Business Intelligence Platform 4.2 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2019-14664 MEDIUM
Enigmail < 2.1 - Cleartext Transmission of Sensitive Information via Crafted Multipart Email Reply
CVSS 6.5
CVE-2019-10363 MEDIUM
Jenkins Configuration as Code Plugin < 1.24 - Cleartext Transmission of Sensitive Information
CVSS 4.9
CVE-2019-5448 HIGH
Yarn < 1.17.3 - Cleartext Transmission of Sensitive Information via HTTP URLs in Lockfile
CVSS 8.1
CVE-2019-13498 HIGH
One Identity Cloud Access Manager 8.1.3 - Cleartext Transmission of Sensitive Information
CVSS 7.4
CVE-2019-12820 MEDIUM
Shenzhen Jisiwei i3 robot vacuum cleaner app 2.0 - Cleartext Transmission of Sensitive Information via HTTP
CVSS 5.6
CVE-2019-10102 HIGH
JetBrains Ktor < 1.1.0 - Cleartext Transmission of Sensitive Information via Build Artifact Resolution
CVSS 8.1
Details
Vulnerabilities 884
Exploit Likelihood High