CVE-2025-32987
Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.16%
- CWE
- CWE-214
- Published
- 2025-04-15
- Last modified
- 2026-03-13
Affected products
- Arctera eDiscovery Platform
Weakness type
Related vulnerabilities
- CVE-2026-81684 — openssl_encrypt before 1.4.9 Information Disclosure via Command Line
- CVE-2026-80158 — Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings
- CVE-2026-65088 — NVIDIA NemoClaw contains a vulnerability where an attacker could cause...
- CVE-2026-76054 — Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17...
- CVE-2026-74873 — openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
- CVE-2026-18915 — Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
- CVE-2026-12139 — Tanium addressed an information disclosure vulnerability in Connect.
- CVE-2026-9494 — ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line