Vulnerabilities > Missing Encryption of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2022-09-21 CVE-2022-3251 Missing Encryption of Sensitive Data vulnerability in Ikus-Soft Minarca
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.
network
low complexity
ikus-soft CWE-311
5.3
2022-09-13 CVE-2022-3174 Missing Encryption of Sensitive Data vulnerability in Ikus-Soft Rdiffweb
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2.
network
low complexity
ikus-soft CWE-311
7.5
2022-08-16 CVE-2022-38194 Missing Encryption of Sensitive Data vulnerability in Esri Portal for Arcgis 10.8.1
In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted.
local
low complexity
esri CWE-311
5.5
2022-08-01 CVE-2022-34307 Missing Encryption of Sensitive Data vulnerability in IBM Cics TX 11.1
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-311
4.3
2022-07-07 CVE-2015-3207 Missing Encryption of Sensitive Data vulnerability in Openshift Origin 3.0.0
In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.
network
low complexity
openshift CWE-311
5.3
2022-06-29 CVE-2021-40642 Missing Encryption of Sensitive Data vulnerability in Textpattern
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php.
network
low complexity
textpattern CWE-311
4.3
2022-06-14 CVE-2021-40650 Missing Encryption of Sensitive Data vulnerability in Softwareag Connx 6.2.0.1269
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
network
low complexity
softwareag CWE-311
6.5
2022-05-25 CVE-2021-27779 Missing Encryption of Sensitive Data vulnerability in Hcltech Versionvault Express 2.0.1
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
network
low complexity
hcltech CWE-311
critical
9.1
2022-05-25 CVE-2021-27783 Missing Encryption of Sensitive Data vulnerability in Hcltech Bigfix Mobile and Bigfix Modern Client Management
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
network
low complexity
hcltech CWE-311
6.5
2022-05-20 CVE-2022-24045 Missing Encryption of Sensitive Data vulnerability in Siemens products
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).
network
low complexity
siemens CWE-311
6.5