Vulnerabilities > Missing Encryption of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2019-01-07 CVE-2018-5481 Missing Encryption of Sensitive Data vulnerability in Netapp Oncommand Unified Manager
OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certain circumstances making it vulnerable to impersonation via man-in-the-middle (MITM) attacks.
network
high complexity
netapp CWE-311
7.4
2019-01-03 CVE-2018-16879 Missing Encryption of Sensitive Data vulnerability in Redhat Ansible Tower
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ.
network
low complexity
redhat CWE-311
critical
9.8
2019-01-02 CVE-2018-20100 Missing Encryption of Sensitive Data vulnerability in August Connect and August Connect Firmware
An issue was discovered on August Connect devices.
network
low complexity
august CWE-311
critical
9.8
2018-12-25 CVE-2018-20465 Missing Encryption of Sensitive Data vulnerability in Craftcms Craft CMS
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
network
low complexity
craftcms CWE-311
7.2
2018-10-23 CVE-2018-16837 Missing Encryption of Sensitive Data vulnerability in multiple products
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen.
local
low complexity
redhat debian suse CWE-311
7.8
2018-10-10 CVE-2018-17915 Missing Encryption of Sensitive Data vulnerability in Xiongmaitech Xmeye P2P Cloud Server
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication.
network
low complexity
xiongmaitech CWE-311
critical
9.8
2018-09-26 CVE-2018-1683 Missing Encryption of Sensitive Data vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication.
network
low complexity
ibm CWE-311
7.5
2018-09-19 CVE-2018-3826 Missing Encryption of Sensitive Data vulnerability in Elastic Elasticsearch
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API.
network
low complexity
elastic CWE-311
6.5
2018-09-11 CVE-2018-6976 Missing Encryption of Sensitive Data vulnerability in VMWare Workspace ONE
The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database.
network
low complexity
vmware CWE-311
5.3
2018-09-11 CVE-2018-6975 Missing Encryption of Sensitive Data vulnerability in VMWare Intelligent HUB
The AirWatch Agent for iOS prior to 5.8.1 contains a data protection vulnerability whereby the files and keychain entries in the Agent are not encrypted.
local
low complexity
vmware CWE-311
5.5