Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2019-07-22 CVE-2019-13100 Cleartext Storage of Sensitive Information vulnerability in Send-Anywhere Send Anywhere 9.4.18
The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_device.xml.
network
low complexity
send-anywhere CWE-312
4.0
2019-07-22 CVE-2019-13099 Cleartext Storage of Sensitive Information vulnerability in Momo Project Momo 2.1.9
The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.
network
low complexity
momo-project CWE-312
4.0
2019-07-11 CVE-2019-10351 Cleartext Storage of Sensitive Information vulnerability in Jenkins Caliper CI 2.3
Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
8.8
2019-07-11 CVE-2019-10350 Cleartext Storage of Sensitive Information vulnerability in Jenkins Port Allocator
Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
8.8
2019-07-11 CVE-2019-10348 Cleartext Storage of Sensitive Information vulnerability in Jenkins Gogs
Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
8.8
2019-07-03 CVE-2019-9873 Cleartext Storage of Sensitive Information vulnerability in Jetbrains Intellij Idea
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files.
network
low complexity
jetbrains CWE-312
5.0
2019-07-03 CVE-2019-9872 Cleartext Storage of Sensitive Information vulnerability in Jetbrains Intellij Idea
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files.
network
jetbrains CWE-312
4.3
2019-07-03 CVE-2019-9823 Cleartext Storage of Sensitive Information vulnerability in Jetbrains Intellij Idea
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files.
network
low complexity
jetbrains CWE-312
5.0
2019-06-27 CVE-2019-5810 Cleartext Storage of Sensitive Information vulnerability in multiple products
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-312
6.5
2019-06-06 CVE-2018-2028 Cleartext Storage of Sensitive Information vulnerability in IBM products
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information.
network
low complexity
ibm CWE-312
6.5