Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2020-12-23 CVE-2020-35658 Cleartext Storage of Sensitive Information vulnerability in Titanhq Spamtitan
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
network
low complexity
titanhq CWE-312
5.3
2020-12-21 CVE-2020-4843 Cleartext Storage of Sensitive Information vulnerability in IBM Security Secret Server 10.6
IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user.
network
low complexity
ibm CWE-312
4.3
2020-12-14 CVE-2020-17511 Cleartext Storage of Sensitive Information vulnerability in Apache Airflow
In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase.
network
low complexity
apache CWE-312
6.5
2020-12-10 CVE-2019-4738 Cleartext Storage of Sensitive Information vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system.
network
low complexity
ibm CWE-312
6.5
2020-12-09 CVE-2020-26816 Cleartext Storage of Sensitive Information vulnerability in SAP Netweaver Application Server Java
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted.
low complexity
sap CWE-312
4.5
2020-12-08 CVE-2020-25677 Cleartext Storage of Sensitive Information vulnerability in multiple products
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.
local
low complexity
ceph redhat CWE-312
5.5
2020-11-23 CVE-2020-26228 Cleartext Storage of Sensitive Information vulnerability in Typo3
TYPO3 is an open source PHP based web content management system.
network
low complexity
typo3 CWE-312
7.5
2020-11-18 CVE-2020-28917 Cleartext Storage of Sensitive Information vulnerability in View Frontend Statistics Project View Frontend Statistics
An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3.
network
low complexity
view-frontend-statistics-project CWE-312
6.5
2020-11-17 CVE-2020-26551 Cleartext Storage of Sensitive Information vulnerability in Aviatrix Controller 5.3.1516
An issue was discovered in Aviatrix Controller before R5.3.1151.
network
low complexity
aviatrix CWE-312
7.5
2020-11-09 CVE-2020-8276 Cleartext Storage of Sensitive Information vulnerability in Brave
The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows.
local
low complexity
brave CWE-312
5.5