A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which w
Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker coul
SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local authenticated attacker to
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software runn
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, c
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a l
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's
The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session d
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deploymen
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 F
Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user cou
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could all
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A ma
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Clo
NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user o
Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configurati
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form,
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere info
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain
A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated,
Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iN
IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM
E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext with
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which ca
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can
A vulnerability, which was classified as problematic, was found in SourceCodester Guest Management System. Affected is a
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pum
HCL Launch may store certain data for recurring activities in a plain text format.
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server pri
Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk.
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata s
In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root passwo
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and in
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Co
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows
In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Sha
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 978 CVE records associated with CWE-312 in our database. Of these, 40 are critical severity, 260 are high severity, and 445 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started