Show filters
547 Total Results
Displaying 151-160 of 547
Sort by:
Attacker Value
Unknown
CVE-2022-2221
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desktop Manager versions prior to 2022.1.8.
0
Attacker Value
Unknown
CVE-2022-28167
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log
0
Attacker Value
Unknown
CVE-2022-34213
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2022-34202
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2022-34199
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2022-1666
Disclosure Date: June 23, 2022 (last updated February 24, 2025)
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.
0
Attacker Value
Unknown
CVE-2022-2103
Disclosure Date: June 23, 2022 (last updated February 24, 2025)
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.
0
Attacker Value
Unknown
CVE-2022-33953
Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
0
Attacker Value
Unknown
CVE-2020-28865
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
0
Attacker Value
Unknown
CVE-2022-31044
Disclosure Date: June 15, 2022 (last updated February 23, 2025)
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using Rundeck 4.2.0 or 4.2.1 might result in them being written in plaintext to the backend storage. This affects those using any `Storage Converter` plugin. Rundeck 4.3.1 and 4.2.2 have fixed the code and upon upgrade will re-encrypt any plain text values. Version 4.3.0 does not have the vulnerability, but does not include the patch to re-encrypt plain text values if 4.2.0 or 4.2.1 were used. To prevent plaintext credentials from being stored in Rundeck 4.2.0/4.2.1, write access to key storage can be disabled via ACLs. After upgrading to 4.3.1 or later, write access can be restored.
0