CVE-2022-27548
06.07.2022, 21:15
HCL Launch stores user credentials in plain clear text which can be read by a local user.Enginsight
Vendor | Product | Version |
---|---|---|
hcltechsw | hcl_launch | 7.0.5.10 |
hcltechsw | hcl_launch | 7.1.2.6 |
hcltechsw | hcl_launch | 7.2.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-256 - Plaintext Storage of a PasswordStoring a password in plaintext may result in a system compromise.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.