Show filters
187 Total Results
Displaying 1-10 of 187
Sort by:
Attacker Value
Unknown

CVE-2021-40527

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application.
Attacker Value
Unknown

CVE-2021-38911

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.
Attacker Value
Unknown

CVE-2021-40454

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
Rich Text Edit Control Information Disclosure Vulnerability
0
Attacker Value
Unknown

CVE-2021-38915

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
Attacker Value
Unknown

CVE-2021-41302

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
0
Attacker Value
Unknown

CVE-2021-36165

Disclosure Date: September 28, 2021 (last updated February 23, 2025)
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
Attacker Value
Unknown

CVE-2021-29904

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
Attacker Value
Unknown

CVE-2021-38150

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials. This would allow the attacker to compromise the corresponding backend for which the credentials are valid.
Attacker Value
Unknown

CVE-2021-33716

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1.1). An attacker with access to the subnet of the affected device could retrieve sensitive information stored in cleartext.
Attacker Value
Unknown

CVE-2020-19137

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".