Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-02-12 CVE-2021-20409 Cleartext Transmission of Sensitive Information vulnerability in IBM Security Verify Information Queue 1.0.6/1.0.7
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
low complexity
ibm CWE-319
7.5
2021-02-11 CVE-2021-20335 Cleartext Transmission of Sensitive Information vulnerability in Mongodb OPS Manager
For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager versions prior to and including 4.4.12 triggers a bug where Automation thinks SSL is being turned off, and can disable SSL temporarily for members of the cluster.
low complexity
mongodb CWE-319
4.6
2021-02-10 CVE-2020-8355 Cleartext Transmission of Sensitive Information vulnerability in Lenovo Xclarity Administrator
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating.
network
low complexity
lenovo CWE-319
4.9
2021-02-05 CVE-2021-20623 Cleartext Transmission of Sensitive Information vulnerability in Panasonic Video Insight VMS 7.3.2.5/7.5
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request.
network
low complexity
panasonic CWE-319
critical
9.8
2021-02-02 CVE-2020-29662 Cleartext Transmission of Sensitive Information vulnerability in Linuxfoundation Harbor
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
network
low complexity
linuxfoundation CWE-319
5.3
2021-01-26 CVE-2020-25169 Cleartext Transmission of Sensitive Information vulnerability in Reolink products
The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers.
network
low complexity
reolink CWE-319
7.5
2021-01-22 CVE-2021-21270 Cleartext Transmission of Sensitive Information vulnerability in Octopus Octopusdsc
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent.
local
low complexity
octopus CWE-319
5.5
2021-01-21 CVE-2020-4969 Cleartext Transmission of Sensitive Information vulnerability in IBM Security Identity Governance and Intelligence 5.2.6
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-319
5.9
2021-01-13 CVE-2020-4597 Cleartext Transmission of Sensitive Information vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-319
4.3
2021-01-07 CVE-2020-4893 Cleartext Transmission of Sensitive Information vulnerability in IBM Emptoris Strategic Supply Management
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters.
network
high complexity
ibm CWE-319
5.9