VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 12 of 20
  • CVE-2021-0639MedAug 17, 2021
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2020-4871MedJan 19, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.

  • CVE-2019-8790MedOct 27, 2020
    risk 0.36cvss 5.5epss 0.00

    This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.

  • CVE-2020-1493MedAug 17, 2020
    risk 0.36cvss 5.5epss 0.07

    An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this…

  • CVE-2019-5633MedAug 22, 2019
    risk 0.36cvss 5.5epss 0.00

    An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects…

  • CVE-2019-5632MedAug 22, 2019
    risk 0.36cvss 5.5epss 0.00

    An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects…

  • CVE-2017-0493MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions:…

  • CVE-2024-3717MedMay 2, 2024
    risk 0.35cvss 5.3epss 0.01

    The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for…

  • CVE-2024-26559MedFeb 28, 2024
    risk 0.35cvss 5.3epss 0.01

    An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.

  • CVE-2023-0580MedApr 6, 2023
    risk 0.35cvss 5.4epss 0.00

    Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My…

  • CVE-2022-2815MedJan 14, 2023
    risk 0.35cvss 6.5epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.

  • CVE-2022-0724MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2020-5008MedJun 7, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.…

  • CVE-2019-4549MedOct 2, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951.

  • CVE-2019-14957MedOct 1, 2019
    risk 0.35cvss 5.3epss 0.01

    The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.

  • CVE-2026-5666MedApr 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The…

  • CVE-2026-5650MedApr 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried…

  • CVE-2025-10734MedMar 23, 2026
    risk 0.34cvss 5.3epss 0.00

    The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible…

  • CVE-2025-35054MedOct 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the…

  • CVE-2025-46660MedAug 6, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.