Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-10415 Insufficiently Protected Credentials vulnerability in Jenkins Violation Comments to Gitlab
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-09-25 CVE-2019-10414 Insufficiently Protected Credentials vulnerability in Jenkins GIT Changelog
Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-09-25 CVE-2019-10413 Insufficiently Protected Credentials vulnerability in Jenkins Data Theorem Mobile APP Security
Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-09-24 CVE-2019-5505 Insufficiently Protected Credentials vulnerability in Netapp Ontap Select Deploy Administration Utility
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
network
low complexity
netapp CWE-522
critical
9.8
2019-09-23 CVE-2019-15635 Insufficiently Protected Credentials vulnerability in Grafana 5.4.0
An issue was discovered in Grafana 5.4.0.
network
low complexity
grafana CWE-522
4.9
2019-09-21 CVE-2019-16649 Insufficiently Protected Credentials vulnerability in Supermicro products
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices.
network
low complexity
supermicro CWE-522
critical
10.0
2019-09-18 CVE-2019-11664 Insufficiently Protected Credentials vulnerability in Microfocus Service Manager
Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62.
network
low complexity
microfocus CWE-522
6.5
2019-09-18 CVE-2019-11663 Insufficiently Protected Credentials vulnerability in Microfocus Service Manager
Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62.
network
low complexity
microfocus CWE-522
6.5
2019-09-18 CVE-2019-5534 Insufficiently Protected Credentials vulnerability in VMWare Vcenter Server 6.0/6.5/6.7
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties.
network
low complexity
vmware CWE-522
7.7
2019-09-17 CVE-2018-7820 Insufficiently Protected Credentials vulnerability in Schneider-Electric products
A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.
network
low complexity
schneider-electric CWE-522
critical
9.8