Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2019-06-26 CVE-2019-11272 Insufficiently Protected Credentials vulnerability in multiple products
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder.
network
low complexity
vmware debian CWE-522
7.3
2019-06-19 CVE-2019-4385 Insufficiently Protected Credentials vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog.
local
low complexity
ibm CWE-522
6.5
2019-06-19 CVE-2019-11271 Insufficiently Protected Credentials vulnerability in Cloud Foundry Bosh 270.0.0/270.1.0
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database.
local
low complexity
cloud-foundry CWE-522
7.8
2019-06-14 CVE-2019-4239 Insufficiently Protected Credentials vulnerability in IBM Cloud Private
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
5.5
2019-06-13 CVE-2019-11092 Insufficiently Protected Credentials vulnerability in Intel Open Cloud Integrity Tehnology and Openattestation
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
4.4
2019-06-13 CVE-2019-0183 Insufficiently Protected Credentials vulnerability in Intel Open Cloud Integrity Tehnology and Openattestation
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
3.3
2019-06-13 CVE-2019-0182 Insufficiently Protected Credentials vulnerability in Intel Open Cloud Integrity Tehnology and Openattestation
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
3.3
2019-06-13 CVE-2019-0180 Insufficiently Protected Credentials vulnerability in Intel Open Cloud Integrity Tehnology and Openattestation
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
4.4
2019-06-13 CVE-2019-0179 Insufficiently Protected Credentials vulnerability in Intel Open Cloud Integrity Tehnology and Openattestation
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
4.4
2019-06-13 CVE-2019-0178 Insufficiently Protected Credentials vulnerability in Intel Open Cloud Integrity Tehnology and Openattestation
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
local
high complexity
intel CWE-522
3.6