Show filters
593 Total Results
Displaying 201-210 of 593
Sort by:
Attacker Value
Unknown
CVE-2022-34199
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2022-1666
Disclosure Date: June 23, 2022 (last updated February 24, 2025)
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.
0
Attacker Value
Unknown
CVE-2022-2103
Disclosure Date: June 23, 2022 (last updated February 24, 2025)
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.
0
Attacker Value
Unknown
CVE-2022-33953
Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
0
Attacker Value
Unknown
CVE-2020-28865
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
0
Attacker Value
Unknown
CVE-2022-31044
Disclosure Date: June 15, 2022 (last updated February 23, 2025)
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using Rundeck 4.2.0 or 4.2.1 might result in them being written in plaintext to the backend storage. This affects those using any `Storage Converter` plugin. Rundeck 4.3.1 and 4.2.2 have fixed the code and upon upgrade will re-encrypt any plain text values. Version 4.3.0 does not have the vulnerability, but does not include the patch to re-encrypt plain text values if 4.2.0 or 4.2.1 were used. To prevent plaintext credentials from being stored in Rundeck 4.2.0/4.2.1, write access to key storage can be disabled via ACLs. After upgrading to 4.3.1 or later, write access can be restored.
0
Attacker Value
Unknown
CVE-2022-21184
Disclosure Date: June 15, 2022 (last updated February 23, 2025)
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-30231
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6), SICAM GridEdge Essential Intel (All versions < V2.6.6), SICAM GridEdge Essential with GDS ARM (All versions < V2.6.6), SICAM GridEdge Essential with GDS Intel (All versions < V2.6.6). The affected software discloses password hashes of other users upon request. This could allow an authenticated user to retrieve another users password hash.
0
Attacker Value
Unknown
CVE-2022-32518
Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Center Expert (Versions prior to V7.9.0)
0
Attacker Value
Unknown
CVE-2022-32519
Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0)
0