CWE-549Base

Missing Password Field Masking

Draft in the CWE catalog · 13 CVEs mapped

13
CVEs mapped
5.0
Median CVSS
What it is

The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.

Recent examples
4.6cvss
CVE-2026-3314

Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint

Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.8-00; Hitachi Ops Center Analyzer viewpoint: from 10.8.1-00 before 11.0.8-00; Hitachi Infrastructure Analytics Advisor: from 3.2.0-00 before 11.0.8-00.

MEDIUMno explanation yet
0%
epss
5.1cvss
CVE-2025-13175

Insecure Password Storage in Y Soft SafeQ 6

Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers are only those with a password-protected scan workflow connector. This issue affects Y Soft SafeQ 6 in versions before MU106.

MEDIUMno explanation yet
0%
epss
6.5cvss
CVE-2025-42904

Information Disclosure vulnerability in Application Server ABAP

Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-549
Abstraction
Base
Structure
Simple
Status
Draft