This weakness occurs when the application transmits or stores
authentication credentials and uses an insecure method that is susceptible to
unauthorized interception and/or retrieval.
Time of Introduction
Architecture and Design
Implementation
Potential Mitigations
Phase
Description
Use an appropriate security mechanism to protect the
credentials.
Make appropriate use of cryptography to protect the
credentials.
Use industry standards to protect the credentials (e.g. LDAP,
keystore, etc.).
Other Notes
Attackers are potentially able to bypass authentication mechanisms, hijack
a victim's account, and obtain the role and respective access level of the
accounts.