CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,363 vulnerabilities with CWE-522
CVE-2019-4385 MEDIUM
IBM Spectrum Protect Plus 10.1.2 - Info Disclosure
CVSS 6.5
CVE-2019-11271 HIGH
Cloud Foundry BOSH 270.0.0-270.1.0 - Authenticated Credential Exposure via MySQL Database
CVSS 7.8
CVE-2019-4239 MEDIUM
IBM Cloud Private 1.0.0-3.0.1 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2019-11092 MEDIUM
Intel Open Cloud Integrity Technology - Insufficiently Protected Credentials in Attestation Database
CVSS 4.4
CVE-2019-0183 LOW
Intel Open Cloud Integrity Technology - Insufficiently Protected Credentials in Attestation Database
CVSS 3.3
CVE-2019-0182 LOW
Intel Open Cloud Integrity Technology - Insufficiently Protected Credentials in Attestation Database
CVSS 3.3
CVE-2019-0180 MEDIUM
Intel Open Cloud Integrity Technology - Insufficiently Protected Credentials in Attestation Database
CVSS 4.4
CVE-2019-0179 MEDIUM
Intel Open Cloud Integrity Technology - Insufficiently Protected Credentials in Attestation Database
CVSS 4.4
CVE-2019-0178 LOW
Intel Open Cloud Integrity Technology - Insufficiently Protected Credentials in Attestation Database
CVSS 3.6
CVE-2019-0175 MEDIUM
Intel Open Cloud Integrity Technology - Insufficiently Protected Credentials in Attestation Database
CVSS 4.4
CVE-2019-3947 CRITICAL
Fuji Electric V-Server < 6.0.33.0 - Plaintext Database Credential Exposure in Project Files
CVSS 9.8
CVE-2019-6567 MEDIUM
SCALANCE X-200/X-200IRT/X-300/X-414-3E Firmware - Insufficiently Protected Credentials
CVSS 5.5
CVE-2019-10160 CRITICAL
Python 2.7.0-2.7.16, 3.5, 3.6, 3.7, 3.8.0a4-3.8.0b1 - URL Parsing Security Regression
CVSS 9.8
CVE-2019-6452 HIGH
Kyocera Command Center RX TASKalfa4501i/5052ci - Credential Exposure via Test Button
CVSS 8.8
CVE-2019-11367 CRITICAL
AUO Solar Data Recorder <1.3.0 - Auth Bypass
CVSS 9.8
CVE-2019-11369 HIGH
Carel pCOWeb <B1.2.4 - Info Disclosure
CVSS 8.8
CVE-2019-10981 HIGH
CitectSCADA 7.30-7.40 and Vijeo Citect 7.30-7.40 - Authenticated Credential Exposure
CVSS 7.8
CVE-2019-10329 HIGH
Jenkins InfluxDB Plugin <= 1.21 - Insufficiently Protected Credentials
CVSS 8.8
CVE-2019-12452 HIGH
Traefik 1.7.0-1.7.11 - Authenticated Credential Exposure via API Endpoint
CVSS 7.5
CVE-2019-4138 MEDIUM
IBM Spectrum Control 5.2.13-5.3.0.1 - Sensitive Information Exposure via Missing HSTS Enforcement
CVSS 5.9
CVE-2019-5627 HIGH
BlueCats bc_reveal < 5.14 - Insufficiently Protected Credentials in App Cache
CVSS 7.8
CVE-2019-5626 HIGH
BlueCats Reveal < 3.0.19 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2019-5625 HIGH
Eaton Halo Home < 1.11.0 - Insufficiently Protected Credentials
CVSS 7.1
CVE-2019-12046 CRITICAL
LemonLDAP::NG -2.0.3 - Info Disclosure
CVSS 9.8
CVE-2019-10139 HIGH
cockpit-ovirt - Insufficiently Protected Credentials via Plain-Text Password Storage
CVSS 7.8
Details
Vulnerabilities 1,363