Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-08-23 CVE-2022-38665 Insufficiently Protected Credentials vulnerability in Jenkins Collabnet
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
network
low complexity
jenkins CWE-522
6.5
2022-08-23 CVE-2020-35992 Insufficiently Protected Credentials vulnerability in Fiserv Prologue 20201216
Fiserv Prologue through 2020-12-16 does not properly protect the database password.
network
low complexity
fiserv CWE-522
6.5
2022-08-18 CVE-2022-30601 Insufficiently Protected Credentials vulnerability in Intel products
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.
network
low complexity
intel CWE-522
critical
9.8
2022-08-18 CVE-2022-30944 Insufficiently Protected Credentials vulnerability in Intel products
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
5.5
2022-08-18 CVE-2022-26844 Insufficiently Protected Credentials vulnerability in Intel Single Event API
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-522
7.8
2022-08-18 CVE-2022-29507 Insufficiently Protected Credentials vulnerability in Intel Team Blue
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
5.5
2022-08-18 CVE-2022-30296 Insufficiently Protected Credentials vulnerability in Intel Datacenter Group Event
Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-522
7.5
2022-08-16 CVE-2020-10710 Insufficiently Protected Credentials vulnerability in Theforeman Foreman
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer.
local
low complexity
theforeman CWE-522
4.4
2022-08-16 CVE-2022-29959 Insufficiently Protected Credentials vulnerability in Emerson Openbsi 5.9
Emerson OpenBSI through 2022-04-29 mishandles credential storage.
local
low complexity
emerson CWE-522
5.5
2022-08-16 CVE-2022-36307 Insufficiently Protected Credentials vulnerability in Airspan Airvelocity 1500 Firmware 15.18.00.2511/9.3.0.01249
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot.
low complexity
airspan CWE-522
6.8