CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,360 vulnerabilities with CWE-522
CVE-2019-14709 CRITICAL
MicroDigital N-series <6400.0.8.5 - Info Disclosure
CVSS 9.8
CVE-2019-3800 MEDIUM
Cloud Foundry Command Line Interface < 6.45.0 - Insufficiently Protected Credentials in Config File
CVSS 6.3
CVE-2019-10366 MEDIUM
Jenkins Skytap Cloud CI Plugin < 2.06 - Insufficiently Protected Credentials in config.xml
CVSS 6.5
CVE-2019-10361 MEDIUM
Jenkins Maven Release Plugin < 0.14.0 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2019-10345 MEDIUM
Jenkins Configuration as Code Plugin < 1.20 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2019-1020009 HIGH
Fleet < 2.1.1 - Insufficiently Protected SMTP Credentials
CVSS 7.5
CVE-2019-1010241 MEDIUM
Jenkins Credentials Binding Plugin 1.17 - Info Disclosure
CVSS 6.5
CVE-2019-8932 HIGH
rdbrck shift < 3.4.3 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2019-1010308 CRITICAL
Aquaverde GmbH Aquarius CMS <4.1.1 - Info Disclosure
CVSS 9.8
CVE-2019-9657 HIGH
Alarm.com ADC-V522IR 0100b9 - Info Disclosure
CVSS 7.8
CVE-2019-10347 HIGH
Jenkins Mashup Portlets < 1.0.9 - Insufficiently Protected Credentials
CVSS 8.8
CVE-2019-12171 HIGH
Dropbox <71.4.108.0 - Memory Corruption
CVSS 7.8
CVE-2019-13400 CRITICAL
Fortinet FCM-MB40 v1.2.0.0 - Insufficiently Protected Credentials via Cleartext Storage
CVSS 9.8
CVE-2019-9873 CRITICAL
JetBrains IntelliJ IDEA Ultimate - Info Disclosure
CVSS 9.8
CVE-2019-9872 HIGH
JetBrains IntelliJ IDEA Ultimate - Info Disclosure
CVSS 8.1
CVE-2019-9823 CRITICAL
JetBrains IntelliJ IDEA - Info Disclosure
CVSS 9.8
CVE-2019-12847 HIGH
JetBrains Hub < 2018.4.11298 - Cleartext Password Exposure in Audit Logs
CVSS 7.2
CVE-2019-13179 HIGH
Calamares 3.1-3.2.10 - Unprotected User Data Exposure via Insecure Keyfile Permissions
CVSS 7.5
CVE-2019-7260 CRITICAL
Linear eMerge E3-Series - Info Disclosure
CVSS 9.8
CVE-2019-7271 CRITICAL
Nortek Linear eMerge 50P/5000P - Info Disclosure
CVSS 9.8
CVE-2019-13054 MEDIUM
Logitech R500 Firmware - Insufficiently Protected Credentials Leading to Keystroke Injection
CVSS 6.5
CVE-2019-11272 HIGH
Spring Security 4.2.x < 4.2.13 - Authentication Bypass via Null Password
CVSS 7.3
CVE-2019-4385 MEDIUM
IBM Spectrum Protect Plus 10.1.2 - Info Disclosure
CVSS 6.5
CVE-2019-11271 HIGH
Cloud Foundry BOSH 270.0.0-270.1.0 - Authenticated Credential Exposure via MySQL Database
CVSS 7.8
CVE-2019-4239 MEDIUM
IBM Cloud Private 1.0.0-3.0.1 - Insufficiently Protected Credentials
CVSS 5.5
Details
Vulnerabilities 1,360