The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Use an appropriate security mechanism to protect the credentials.
Make appropriate use of cryptography to protect the credentials.
Use industry standards to protect the credentials (e.g. LDAP, keystore, etc.).
Our security experts can help you identify and remediate CWE-522 vulnerabilities in your codebase.
Get Security Assessment