Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2020-4624

Published Nov 30, 2020

IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could allow an attacker to decrypt sensitive information.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8897

Published Nov 16, 2020

A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and ot…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4778

Published Oct 12, 2020

IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4325

Published Oct 6, 2020

"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9491

Published Oct 1, 2020

In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpReq…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11031

Published Sep 23, 2020

In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4614

Published Sep 22, 2020

IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 184927.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4613

Published Sep 22, 2020

IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184925.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14517

Published Sep 16, 2020

Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-6874

Published Sep 1, 2020

A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account cr…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4174

Published Aug 27, 2020

IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 17468…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4169

Published Aug 27, 2020

IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 17440…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8912

Published Aug 11, 2020

A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-8911

Published Aug 11, 2020

A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Auth…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 685 CVEsPage 20 of 28