Show filters
441 Total Results
Displaying 241-250 of 441
Sort by:
Attacker Value
Unknown

CVE-2021-42066

Disclosure Date: December 14, 2021 (last updated February 23, 2025)
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be able to completely compromise confidentiality, integrity, and availability of the application.
Attacker Value
Unknown

CVE-2021-41090

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance config are exposed in plaintext over two endpoints: metrics instance configs defined in the base YAML file are exposed at `/-/config` and metrics instance configs defined for the scraping service are exposed at `/agent/api/v1/configs/:key`. Inline secrets will be exposed to anyone being able to reach these endpoints. If HTTPS with client authentication is not configured, these endpoints are accessible to unauthenticated users. Secrets found in these sections are used for delivering metrics to a Prometheus Remote Write system, authenticating against a system for discovering Prometheus targets, and authenticating against a system for collecting metrics. This does not apply for non-inlined secrets, such as `*_file` based secrets. This issue is patched in Grafana Agent versions…
Attacker Value
Unknown

CVE-2021-34544

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.
Attacker Value
Unknown

CVE-2021-38949

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Attacker Value
Unknown

CVE-2021-37157

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.
Attacker Value
Unknown

CVE-2020-10053

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as database credentials in configuration files. A local attacker with access to the configuration files could use this information to launch further attacks.
Attacker Value
Unknown

CVE-2021-42370

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser to display HTML password input fields.)
Attacker Value
Unknown

CVE-2021-25502

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.
Attacker Value
Unknown

CVE-2020-15935

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.
Attacker Value
Unknown

CVE-2021-37842

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.