Show filters
282 Total Results
Displaying 91-100 of 282
Sort by:
Attacker Value
Unknown

CVE-2021-37842

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has a tombstone purger time-stamp attached to it.
Attacker Value
Unknown

CVE-2021-42763

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.
Attacker Value
Unknown

CVE-2021-40527

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application.
Attacker Value
Unknown

CVE-2021-29786

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.
Attacker Value
Unknown

CVE-2021-38422

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.
Attacker Value
Unknown

CVE-2021-38911

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.
Attacker Value
Unknown

CVE-2021-40454

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
Rich Text Edit Control Information Disclosure Vulnerability
0
Attacker Value
Unknown

CVE-2021-38915

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
Attacker Value
Unknown

CVE-2021-41302

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
0
Attacker Value
Unknown

CVE-2021-36165

Disclosure Date: September 28, 2021 (last updated February 23, 2025)
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.