CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 10 of 19
- CVE-2022-34339MEDIUMCVSS 6.5EG 6.52022-11-03
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
- CVE-2022-2805MEDIUMCVSS 6.5EG 6.52022-10-19
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.
- CVE-2022-3540MEDIUMCVSS 6.5EG 6.52022-10-17
An issue has been discovered in hunter2 affecting all versions before 2.1.0. Improper handling of auto-completion input allows an authenticated attacker to extract other users email addresses
- CVE-2022-29620MEDIUMCVSS 6.5EG 6.52022-06-07
FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability
- CVE-2021-45491MEDIUMCVSS 6.5EG 6.52022-03-28
3CX System through 2022-03-17 stores cleartext passwords in a database.
- CVE-2021-35036MEDIUMCVSS 6.5EG 6.52022-03-01
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
- CVE-2021-41090MEDIUMCVSS 6.5EG 6.52021-12-08
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance config are exposed in pl…
- CVE-2021-34544MEDIUMCVSS 6.5EG 6.52021-12-07
An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device. Fix…
- CVE-2021-29786MEDIUMCVSS 6.5EG 6.52021-10-27
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
- CVE-2021-38915MEDIUMCVSS 6.5EG 6.52021-10-12
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
- CVE-2021-38150MEDIUMCVSS 6.5EG 6.52021-09-14
When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as cred…
- CVE-2021-33716MEDIUMCVSS 6.5EG 6.52021-09-14
A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1.1). An attacker with access to the subnet of the affected device could retrieve sensitive informat…
- CVE-2020-4980MEDIUMCVSS 6.5EG 6.52021-07-16
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
- CVE-2021-29481MEDIUMCVSS 6.5EG 6.52021-06-29
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side sessions results in unencrypted, but signed, data being set as cookie values. This means that if something sensitive g…
- CVE-2021-28979MEDIUMCVSS 6.5EG 6.52021-06-16
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is cl…
- CVE-2021-31855MEDIUMCVSS 6.5EG 6.52021-06-02
KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content…
- CVE-2021-21734MEDIUMCVSS 6.5EG 6.52021-05-28
Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10 F822 V1.4.3T6, ZXA10 F819 V1.2.1T5, ZXA…
- CVE-2021-29683MEDIUMCVSS 6.5EG 6.52021-05-20
IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.
- CVE-2020-22783MEDIUMCVSS 6.5EG 6.52021-04-28
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.
- CVE-2021-27210MEDIUMCVSS 6.5EG 6.52021-02-13
TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.
- CVE-2021-20358MEDIUMCVSS 6.5EG 6.52021-02-08
IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files. IBM X-Force ID: 194965.
- CVE-2021-1265MEDIUMCVSS 6.5EG 6.52021-01-20
A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to…
- CVE-2020-17511MEDIUMCVSS 6.5EG 6.52020-12-14
In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.
- CVE-2019-4738MEDIUMCVSS 6.5EG 6.52020-12-10
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM …
- CVE-2020-28917MEDIUMCVSS 6.5EG 6.52020-11-18
An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website,…
- CVE-2020-4619MEDIUMCVSS 6.5EG 6.52020-09-22
IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.
- CVE-2019-13021MEDIUMCVSS 6.5EG 6.52020-05-14
The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation…
- CVE-2019-16062MEDIUMCVSS 6.5EG 6.52020-03-19
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.
- CVE-2019-14886MEDIUMCVSS 6.5EG 6.52020-03-05
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and …
- CVE-2020-6794MEDIUMCVSS 6.5EG 6.52020-03-02
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a …
- CVE-2016-3192MEDIUMCVSS 6.5EG 6.52019-11-26
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
- CVE-2019-5848MEDIUMCVSS 6.5EG 6.52019-11-25
Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2019-17106MEDIUMCVSS 6.5EG 6.52019-10-08
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
- CVE-2019-15508MEDIUMCVSS 6.5EG 6.52019-08-23
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to th…
- CVE-2019-15507MEDIUMCVSS 6.5EG 6.52019-08-23
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to t…
- CVE-2019-3753MEDIUMCVSS 6.5EG 6.52019-08-20
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings me…
- CVE-2019-13100MEDIUMCVSS 6.5EG 6.52019-07-22
The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.androi…
- CVE-2019-13099MEDIUMCVSS 6.5EG 6.52019-07-22
The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.
- CVE-2019-5810MEDIUMCVSS 6.5EG 6.52019-06-27
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2019-1627MEDIUMCVSS 6.5EG 6.52019-06-20
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on t…
- CVE-2018-2028MEDIUMCVSS 6.5EG 6.52019-06-06
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
- CVE-2018-11242MEDIUMCVSS 6.5EG 6.52018-05-20
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databa…
- CVE-2017-14990MEDIUMCVSS 6.5EG 6.52017-10-03
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging d…
- CVE-2026-43942MEDIUMCVSS 5.5EG 6.52026-05-08
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the …
- CVE-2026-66781MEDIUMCVSS 5.4EG 6.52026-08-18
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communica…
- CVE-2022-26778MEDIUMCVSS 5.3EG 6.52022-03-10
Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configuration of the backup configuration. This could allow a Windows user (who has sufficient privileges) to access a network fil…
- CVE-2020-6648MEDIUMCVSS 5.3EG 6.52020-10-21
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as …
- CVE-2023-20059MEDIUMCVSS 4.3EG 6.52023-03-23
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged…
- CVE-2022-29832MEDIUMCVSS 3.7EG 6.52022-11-25
Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GX Works2 all versions and GX Developer versions 8.40S and later allows a remote unauthenticated att…
- CVE-2021-21547MEDIUMCVSS 6.4EG 6.42021-04-30
Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere Administrator are sto…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →