Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2024-46480HIGHAn NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privEPSS 0.5%CVE-2023-32280MEDIUMInsufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated EPSS 0.5%CVE-2023-1574MEDIUMInformation disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on WindoEPSS 0.5%CVE-2025-27192LOWAdobe Commerce | Insufficiently Protected Credentials (CWE-522)EPSS 0.5%CVE-2026-82434CRITICALApache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to LogsEPSS 0.5%CVE-2025-34196CRITICALVasion Print (formerly PrinterLogic) Hardcoded PrinterLogic CA Private Key and Hardcoded PasswordEPSS 0.5%CVE-2023-25531HIGHNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploEPSS 0.5%CVE-2024-5176CRITICALVulnerability in Welch Allyn Configuration Tool SoftwareEPSS 0.5%CVE-2026-64918MEDIUMMicrosoft Office Spoofing VulnerabilityEPSS 0.5%CVE-2023-29168LOWPTC Vuforia Studio Insufficiently Protected CredentialsEPSS 0.5%CVE-2023-31187MEDIUMAvaya IX Workforce Engagement - CWE-522: Insufficiently Protected CredentialsEPSS 0.5%CVE-2026-59891CRITICALCredential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registryEPSS 0.5%CVE-2026-32633CRITICALGlances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`EPSS 0.5%CVE-2022-41564MEDIUMTIBCO Operational Intelligence Hawk Redtail Credential Exposure VulnerabilityEPSS 0.5%CVE-2024-41771HIGHIBM Engineering Requirements Management DOORS Next information disclosureEPSS 0.5%CVE-2019-17082CRITICALInsufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris sEPSS 0.5%CVE-2024-41770HIGHIBM Engineering Requirements Management DOORS Next information disclosureEPSS 0.5%CVE-2025-52549CRITICALPredictable root linux password generationEPSS 0.5%CVE-2022-26341HIGHInsufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R)EPSS 0.5%CVE-2025-62157HIGHArgo Workflows exposes artifact repository credentials in workflow-controller logsEPSS 0.5%