Skip to main content

Threats Tagged 'cwe-327'

View all threats tagged with 'cwe-327'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-327

Threats Tagged 'cwe-327'

Click on any threat for detailed analysis and mitigation recommendations

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

Join the discussion

Imprivata Enterprise Access Management (EAM) versions 26.2.6 and below do not support rotation of the RSA key pair used to generate the appliance's X.509 certificate. This means the same key pair is used indefinitely, violating cryptographic best practices. If an attacker obtains the private key, they can impersonate the appliance to any trusted endpoint, intercepting authentication traffic and potentially decrypting past communications if perfect forward secrecy is not enforced. The vendor is aware but has not provided a fix or timeline. Until resolved, users should protect the private key and enforce perfect forward secrecy.

Join the discussion

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.

Join the discussion

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Join the discussion

IBM Cognos Analytics versions 12.1.0 through 12.1.3 FP1 and 12.0.4 through 12.0.4 FP2 contain a vulnerability due to the use of a broken or risky cryptographic algorithm. This flaw could allow an attacker on a shared network to obtain sensitive information by exploiting insecure network communication. The vulnerability has a medium severity with a CVSS score of 5.9. No official patch or remediation details are provided in the available data.

Join the discussion

IBM Cognos Analytics versions 12.0.4 and 12.1.0 contain a vulnerability due to failure to properly enable HTTP Strict Transport Security (HSTS). This weakness could allow a remote attacker to intercept sensitive information via man-in-the-middle techniques. The issue is classified under CWE-327 for use of a broken or risky cryptographic algorithm. The vulnerability has a medium severity with a CVSS score of 5.9.

Join the discussion

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Join the discussion

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

Join the discussion

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

Join the discussion

CVE-2026-15638 is a critical vulnerability in Delinea Secret Server (On-Prem) versions 10.5.1 through 12.1.3. It allows an unauthenticated user with access to the server to perform a padding oracle attack to decrypt or encrypt data using one of the server's cryptographic keys. The cryptographic key itself is not exposed by this vulnerability.

Join the discussion

Showing 1 to 10 of 123 results

Filters:Tag: cwe-327
Page 1 of 13
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses