Show filters
735 Total Results
Displaying 301-310 of 735
Sort by:
Attacker Value
Unknown
CVE-2020-35992
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the configuration file. This would yield cleartext credentials for the database (to gain access to financial records of customers stored within the database), and in some cases would allow remote login to the database.
0
Attacker Value
Unknown
CVE-2021-3513
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
0
Attacker Value
Unknown
CVE-2021-36783
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Rancher Rancher versions prior to 2.6.4; Rancher versions prior to 2.5.13.
0
Attacker Value
Unknown
CVE-2022-30944
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2022-30601
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.
0
Attacker Value
Unknown
CVE-2022-30296
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.
0
Attacker Value
Unknown
CVE-2022-29507
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2022-26844
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2020-10710
Disclosure Date: August 16, 2022 (last updated February 24, 2025)
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.
0
Attacker Value
Unknown
CVE-2022-29959
Disclosure Date: August 16, 2022 (last updated February 24, 2025)
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.
0