VYPR

CWE-525

Use of Web Browser Cache Containing Sensitive Information

VariantIncomplete

Description

The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (33)

page 2 of 2
  • CVE-2024-22343MedMay 14, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 280190.

  • CVE-2023-46181MedMar 15, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686.

  • CVE-2023-27545MedFeb 29, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 248947.

  • CVE-2023-23469MedFeb 1, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 244504.

  • CVE-2025-27525LowMay 15, 2025
    risk 0.25cvss 3.9epss 0.00

    Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50…

  • CVE-2025-13083LowNov 18, 2025
    risk 0.24cvss 3.7epss 0.00

    Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9,…

  • CVE-2025-52625LowOct 10, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0.

  • CVE-2024-30130LowJul 19, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.

  • CVE-2024-22333LowJun 13, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.

  • CVE-2025-52659LowJan 19, 2026
    risk 0.18cvss 2.8epss 0.00

    HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.

  • CVE-2024-45314LowSep 4, 2024
    risk 0.16cvss 3.6epss 0.00

    Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch…

  • CVE-2024-23571MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this…

  • CVE-2012-2671Jun 17, 2012
    risk 0.00cvss epss 0.02

    The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.