CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,360 vulnerabilities with CWE-522
CVE-2020-2131 MEDIUM
Jenkins Harvest SCM Plugin <= 0.5.1 - Insufficiently Protected Credentials in Job config.xml
CVSS 6.5
CVE-2020-2130 MEDIUM
Jenkins Harvest SCM Plugin <= 0.5.1 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2020-2129 MEDIUM
Jenkins Eagle Tester Plugin < 1.0.9 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2020-2128 MEDIUM
Jenkins ECX Copy Data Management Plugin < 1.9 - Unencrypted Password Storage in Job Config
CVSS 4.3
CVE-2020-2127 MEDIUM
Jenkins BMC Release Package and Deployment Plugin < 1.1 - Unencrypted Credential Storage
CVSS 4.3
CVE-2020-2126 MEDIUM
Jenkins DigitalOcean Plugin <= 1.1 - Insufficiently Protected Credentials
CVSS 4.3
CVE-2020-2125 MEDIUM
Jenkins Debian Package Builder Plugin < 1.6.11 - Insufficiently Protected Credentials
CVSS 4.3
CVE-2020-2124 MEDIUM
Jenkins Dynamic Extended Choice Parameter Plugin < 1.0.1 - Insufficiently Protected Credentials
CVSS 4.3
CVE-2020-2119 MEDIUM
Jenkins Azure AD Plugin <= 1.1.2 - Insufficiently Protected Credentials
CVSS 5.3
CVE-2020-2114 HIGH
Jenkins S3 Publisher Plugin <= 0.11.4 - Plaintext Credential Exposure in Global Configuration
CVSS 7.5
CVE-2020-6969 CRITICAL
C-More EA9 Series Firmware < 6.53 - Unprotected Credential Exposure in Project Files
CVSS 9.8
CVE-2020-7909 HIGH
JetBrains TeamCity <2019.1.5 - Info Disclosure
CVSS 7.5
CVE-2020-2107 MEDIUM
Jenkins Fortify Plugin < 19.1.29 - Insufficiently Protected Credentials in Job config.xml
CVSS 4.3
CVE-2020-6961 CRITICAL
ApexPro Telemetry Server <4.2 - Info Disclosure
CVSS 10.0
CVE-2020-7233 CRITICAL
KMS Controls BAC-A1616BC BACnet - Insufficiently Protected Credentials via Cleartext Password in BC_Logon.swf
CVSS 9.8
CVE-2020-2095 MEDIUM
Jenkins Redgate SQL Change Automation Plugin < 2.0.4 - Insufficiently Protected Credentials in Job Config
CVSS 4.3
CVE-2019-17082 CRITICAL
OpenText AccuRev 2017.1.1 - Auth Bypass
CVE-2019-14840 HIGH
Red Hat Decision Manager - Insufficiently Protected Credentials via Auto-Complete Enabled Password Fields
CVSS 7.5
CVE-2019-4724 HIGH
IBM Cognos Analytics <11.1 - Info Disclosure
CVSS 7.5
CVE-2019-4723 HIGH
IBM Cognos Analytics <11.2 - Info Disclosure
CVSS 7.5
CVE-2019-25030 MEDIUM
Versa Director, Versa Analytics, VOS < - Info Disclosure
CVSS 5.5
CVE-2019-10225 MEDIUM
OpenShift Container Platform 4.2 - Info Disclosure
CVSS 6.3
CVE-2019-14480 CRITICAL
AdRem NetCrunch 10.6.0.4587 - Auth Bypass
CVSS 9.8
CVE-2019-14477 MEDIUM
AdRem NetCrunch 10.6.0.4587 - Info Disclosure
CVSS 5.5
CVE-2019-16211 CRITICAL
Brocade SANnav <2.1.0 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 1,360