CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,359 vulnerabilities with CWE-522
CVE-2023-50291 HIGH
Apache Solr 6.0.0-8.11.2 and 9.0.0-9.2.9 - Authenticated Credential Exposure via /admin/info/properties Endpoint
CVSS 7.5
CVE-2023-29055 HIGH
Apache Kylin <4.0.3 - Info Disclosure
CVSS 7.5
CVE-2023-6573 MEDIUM
HPE OneView < 8.70 - Insufficiently Protected Credentials during Restore
CVSS 5.5
CVE-2023-49106 MEDIUM
Hitachi Device Manager <8.8.5-04 - Info Disclosure
CVSS 4.6
CVE-2023-50125 MEDIUM
Hozard Alarm System v1.0 - Unauthenticated Default Credential Exposure
CVSS 5.9
CVE-2023-29447 MEDIUM
PTC Kepware Kepserverex - Insufficiently Protected Credentials
CVSS 5.7
CVE-2023-6421 HIGH
WordPress Download Mgr <3.2.83 - Info Disclosure
CVSS 7.5
CVE-2023-47741 MEDIUM
IBM i 7.3-7.5 and Db2 Mirror for i 7.4-7.5 - Insufficiently Protected Credentials in Web Browser Client
CVSS 5.3
CVE-2023-6791 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 4.9
CVE-2023-50770 MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Insufficiently Protected Credentials
CVSS 6.7
CVE-2023-47577 CRITICAL
Relyum RELY-PCIe and RELY-REC - Unauthenticated Password Change
CVSS 9.8
CVE-2023-47722 MEDIUM
IBM API Connect V10.0.5.3 and V10.0.6.0 - Insufficiently Protected Credentials
CVSS 6.2
CVE-2023-32268 HIGH
Micro Focus Filr < 23.2.1 - Authenticated Proxy Administrator Credential Exposure
CVSS 7.2
CVE-2023-49280 HIGH
XWiki Change Request < 1.10 - Authenticated Password Hash Exposure via Change Request Export
CVSS 7.7
CVE-2023-24047 MEDIUM
Connectize AC21000 G6 <641.139.1 - Privilege Escalation
CVSS 6.8
CVE-2023-44300 MEDIUM
Dell DM5500 5.14.0.0 - Info Disclosure
CVSS 5.5
CVE-2023-49653 MEDIUM
Jenkins Jira Plugin < 3.11 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2023-6254 HIGH
OTRS 8.0.1-8.0.37 - Insufficiently Protected Credentials via AgentInterface and ExternalInterface
CVSS 8.1
CVE-2023-44303 HIGH
RVTools 3.9.2-4.5.0 - Unauthenticated Sensitive Data Exposure in Password Encryption Utility
CVSS 7.5
CVE-2023-41676 MEDIUM
FortiSIEM < 6.7.5 and 7.0.0 - Unauthenticated Sensitive Information Exposure via Windows Agent Logs
CVSS 4.3
CVE-2023-26221 MEDIUM
TIBCO Spotfire Analyst 12.3.0, 12.4.0, 12.5.0 - Insufficiently Protected Credentials via Crafted Analyst Files
CVSS 5.0
CVE-2023-38548 MEDIUM
Veeam ONE - Unprotected Credential Exposure via Web Client
CVSS 4.3
CVE-2023-38328 MEDIUM
eGroupWare 17.1.20190111 - Info Disclosure
CVSS 4.9
CVE-2023-43905 HIGH
writercms 1.1.0 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2023-46651 MEDIUM
Jenkins Warnings Plugin <10.5.0 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 1,359