A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes su
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may exp
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials i
The database access credentials configured during installation are stored in a special table, and are encrypted with a s
IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in pl
IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that
Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOC
Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a co
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials
A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm sys
An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credential
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login pr
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authenticatio
HPE OneView may have a missing passphrase during restore.
EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the project
Azure Identity Library for .NET Information Disclosure Vulnerability
Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images fro
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be rea
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Re
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter fir
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version
AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue wi
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Thi
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privile
Claris International has successfully resolved an issue of potentially exposing password information to front-end websit
IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication
IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administr
In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors,
Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credent
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected dev
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obta
IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local u
IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-F
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files
IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the
Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started