Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-09-13 CVE-2022-39816 Insufficiently Protected Credentials vulnerability in Nokia 1350 Optical Management System 14.2
In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page.
network
low complexity
nokia CWE-522
6.5
2022-09-09 CVE-2022-36617 Insufficiently Protected Credentials vulnerability in Haystacksoftware ARQ Backup 7.19.5.0
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption.
network
low complexity
haystacksoftware CWE-522
4.9
2022-09-07 CVE-2021-36783 Insufficiently Protected Credentials vulnerability in Suse Rancher
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints.
network
low complexity
suse CWE-522
critical
9.9
2022-09-02 CVE-2022-34371 Insufficiently Protected Credentials vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability.
network
low complexity
dell CWE-522
critical
9.8
2022-09-01 CVE-2021-39045 Insufficiently Protected Credentials vulnerability in multiple products
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields.
local
low complexity
ibm netapp CWE-522
5.5
2022-08-30 CVE-2022-27560 Insufficiently Protected Credentials vulnerability in Hcltech Versionvault Express 2.0.1/2.1.0
HCL VersionVault Express exposes administrator credentials.
network
low complexity
hcltech CWE-522
6.5
2022-08-26 CVE-2021-20260 Insufficiently Protected Credentials vulnerability in Theforeman Foreman
A flaw was found in the Foreman project.
local
low complexity
theforeman CWE-522
7.8
2022-08-24 CVE-2022-34837 Insufficiently Protected Credentials vulnerability in ABB Zenon
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
local
low complexity
abb CWE-522
6.1
2022-08-24 CVE-2022-34838 Insufficiently Protected Credentials vulnerability in ABB Zenon
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes.
local
low complexity
abb CWE-522
8.4
2022-08-23 CVE-2022-38663 Insufficiently Protected Credentials vulnerability in Jenkins GIT
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
network
low complexity
jenkins CWE-522
6.5