Vulnerabilities > Missing Encryption of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2019-11-08 CVE-2019-16206 Missing Encryption of Sensitive Data vulnerability in Broadcom Brocade Sannav 1.1.0/1.1.1
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.
local
low complexity
broadcom CWE-311
5.5
2019-09-17 CVE-2019-4171 Missing Encryption of Sensitive Data vulnerability in IBM Cognos Controller
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies.
network
high complexity
ibm CWE-311
3.7
2019-09-17 CVE-2019-9681 Missing Encryption of Sensitive Data vulnerability in Dahuasecurity products
Online upgrade information in some firmware packages of Dahua products is not encrypted.
network
low complexity
dahuasecurity CWE-311
5.3
2019-09-13 CVE-2019-13922 Missing Encryption of Sensitive Data vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1).
network
low complexity
siemens CWE-311
2.7
2019-07-08 CVE-2019-12924 Missing Encryption of Sensitive Data vulnerability in Mailenable
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user.
network
low complexity
mailenable CWE-311
critical
9.8
2019-07-03 CVE-2019-10103 Missing Encryption of Sensitive Data vulnerability in Jetbrains Kotlin
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack.
network
high complexity
jetbrains CWE-311
8.1
2019-06-26 CVE-2019-6169 Missing Encryption of Sensitive Data vulnerability in Lenovo Service Bridge
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.
network
low complexity
lenovo CWE-311
7.5
2019-06-12 CVE-2019-0307 Missing Encryption of Sensitive Data vulnerability in SAP Solution Manager 7.2
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default.
low complexity
sap CWE-311
2.4
2019-06-07 CVE-2018-10698 Missing Encryption of Sensitive Data vulnerability in Moxa Awk-3121 Firmware 1.14
An issue was discovered on Moxa AWK-3121 1.14 devices.
network
low complexity
moxa CWE-311
critical
9.8
2019-06-07 CVE-2018-10694 Missing Encryption of Sensitive Data vulnerability in Moxa Awk-3121 Firmware 1.14
An issue was discovered on Moxa AWK-3121 1.14 devices.
network
high complexity
moxa CWE-311
8.1