Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2024-06-13 CVE-2024-25052 Insufficiently Protected Credentials vulnerability in IBM Jazz Reporting Service 7.0.3
IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user.
local
low complexity
ibm CWE-522
4.4
2024-06-11 CVE-2024-35208 Insufficiently Protected Credentials vulnerability in Siemens Sinec Traffic Analyzer 1.1
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2).
local
low complexity
siemens CWE-522
5.5
2024-06-10 CVE-2024-37051 Insufficiently Protected Credentials vulnerability in Jetbrains products
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
network
low complexity
jetbrains CWE-522
7.5
2024-06-06 CVE-2024-5657 Insufficiently Protected Credentials vulnerability in Born05 Two-Factor Authentication 3.3.1/3.3.2/3.3.3
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
network
high complexity
born05 CWE-522
8.1
2024-05-14 CVE-2023-42955 Insufficiently Protected Credentials vulnerability in Claris Filemaker Server
Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role.
network
low complexity
claris CWE-522
4.9
2024-05-08 CVE-2024-28971 Insufficiently Protected Credentials vulnerability in Dell Openmanage Enterprise Update Manager
Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file.
network
low complexity
dell CWE-522
4.9
2024-05-07 CVE-2024-4536 Insufficiently Protected Credentials vulnerability in Eclipse EDC Connector
In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from the vault. In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have identified a security vulnerability in the EDC Connector component ( https://github.com/eclipse-edc/Connector ) regarding the OAuth2-protected data sink feature.
high complexity
eclipse CWE-522
5.3
2024-05-02 CVE-2024-3543 Insufficiently Protected Credentials vulnerability in Progress Loadmaster 7.2.48.11
Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.
network
low complexity
progress CWE-522
7.5
2024-04-29 CVE-2024-28961 Insufficiently Protected Credentials vulnerability in Dell Openmanage Enterprise 4.0/4.0.1
Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability.
local
low complexity
dell CWE-522
7.8
2024-03-18 CVE-2022-47037 Insufficiently Protected Credentials vulnerability in Siklu TG Firmware
Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.
network
low complexity
siklu CWE-522
7.5