Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit th
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Forc
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
HCL VersionVault Express exposes administrator credentials.
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certif
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious acto
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreS
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encodin
The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage v
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that co
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device co
Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenk
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS
SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to dis
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directo
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is vi
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave a
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authentic
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomple
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes th
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could all
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0
BigFix Web Reports authorized users may see SMTP credentials in clear text.
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user cre
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application disclo
HCL Launch stores user credentials in plain clear text which can be read by a local user.
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorr
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attacker
Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 thr
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to re
An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that e
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain ac
A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensit
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensit
Plaintext storage of a password vulnerability exists in +F FS040U software versions v2.3.4 and earlier, which may allow
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satell
Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900
Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenk
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files o
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its glob
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.x
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started