CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,360 vulnerabilities with CWE-522
CVE-2021-38938 MEDIUM
IBM HATS <9.6.1.4, <9.7.0.3 - Info Disclosure
CVSS 6.2
CVE-2021-33589 HIGH
Ribose RNP <0.15.1 - Info Disclosure
CVSS 7.5
CVE-2021-36204 HIGH
Johnsoncontrols Metasys Application And Data Server < 10.1.6 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2021-36783 CRITICAL
SUSE Rancher 2.5.0-2.5.12 - Authenticated Cleartext Credential Exposure via API Endpoints
CVSS 9.9
CVE-2021-39045 MEDIUM
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 - Insufficiently Protected Credentials via Autocomplete Feature
CVSS 5.5
CVE-2021-20260 HIGH
Foreman - Insufficiently Protected Credentials via Datacenter Plugin API
CVSS 7.8
CVE-2021-43767 MEDIUM
PostgreSQL 9.6.0-9.6.23 - Improper Certificate Validation
CVSS 5.9
CVE-2021-3513 HIGH
Keycloak - Confidentiality Info Disclosure
CVSS 7.5
CVE-2021-27785 LOW
HCL Commerce 9.0.1-9.0.1.17 - Insufficiently Protected Credentials
CVSS 3.9
CVE-2021-22640 HIGH
Ovarro TBox < 1.46 - Insufficiently Protected Credentials via Communication Capture
CVSS 7.5
CVE-2021-46440 HIGH
Strapi <3.6.9-4.1.5 - Info Disclosure
CVSS 7.5
CVE-2021-3681 MEDIUM
Ansible Galaxy Collections - Insufficiently Protected Credentials via Build Ignore List
CVSS 5.5
CVE-2021-45892 MEDIUM
Softwarebuero Zauner ARC 4.2.0.4 - Info Disclosure
CVSS 5.9
CVE-2021-32978 HIGH
Automation Direct CLICK PLC CPU <v3.00 - Info Disclosure
CVSS 7.5
CVE-2021-33024 LOW
Philips Vue PACS <12.2 - Info Disclosure
CVSS 3.7
CVE-2021-39046 MEDIUM
IBM Business Automation Workflow 18.0-21.0 and Business Process Manager 8.5-8.6 - Insufficiently Protected Credentials
CVSS 4.9
CVE-2021-23222 MEDIUM
PostgreSQL 9.6 - SSL Certificate Verification Man-in-the-Middle Injection
CVSS 5.9
CVE-2021-22798 HIGH
Conext ComBox Firmware - Insufficiently Protected Credentials
CVSS 7.5
CVE-2021-33107 MEDIUM
Intel(R) AMT SDK <16.0.3 - Info Disclosure
CVSS 4.6
CVE-2021-40360 HIGH
SIMATIC PCS 7 & WinCC - Info Disclosure
CVSS 8.8
CVE-2021-44451 MEDIUM
Apache Superset <= 1.3.2 - Authenticated Database Connection Password Exposure
CVSS 6.5
CVE-2021-23207 MEDIUM
Fresenius Kabi Vigilant MasterMed <2.0.1.3 - Info Disclosure
CVSS 6.5
CVE-2021-23196 HIGH
Agilia Link+ <3.0 - Info Disclosure
CVSS 7.3
CVE-2021-32039 MEDIUM
MongoDB Extension for VS Code <= 0.7.0 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2021-20164 MEDIUM
Trendnet TEW-827DRU 2.08B01 - Unprotected Credential Exposure via smbserver.asp Page
CVSS 4.9
Details
Vulnerabilities 1,360