VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 13 of 20
  • CVE-2022-30361MedOct 25, 2024
    risk 0.34cvss 5.3epss 0.00

    OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s), user type, license…

  • CVE-2024-21258MedOct 15, 2024
    risk 0.34cvss 5.3epss 0.01

    Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-45374MedSep 26, 2024
    risk 0.34cvss 5.3epss 0.00

    The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and…

  • CVE-2024-3723MedJun 11, 2024
    risk 0.34cvss 5.3epss 0.00

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive…

  • CVE-2023-6962MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description…

  • CVE-2024-21117MedApr 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2024-25360MedFeb 12, 2024
    risk 0.34cvss 5.3epss 0.00

    A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

  • CVE-2022-32833MedDec 15, 2022
    risk 0.34cvss 5.3epss 0.01

    An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.

  • CVE-2021-25522MedDec 8, 2021
    risk 0.34cvss 5.3epss 0.00

    Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.

  • CVE-2018-20886MedAug 1, 2019
    risk 0.34cvss 5.3epss 0.00

    cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).

  • CVE-2025-54083MedSep 9, 2025
    risk 0.33cvss epss 0.00

    Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.

  • CVE-2024-5288MedAug 27, 2024
    risk 0.33cvss 5.1epss 0.00

    An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, such as in server-side TLS connections, the connection is…

  • CVE-2024-38496MedJul 15, 2024
    risk 0.33cvss epss 0.00

    The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.

  • CVE-2022-44581MedMay 17, 2024
    risk 0.33cvss 5.0epss 0.01

    Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.

  • CVE-2023-29261MedSep 5, 2023
    risk 0.33cvss 5.1epss 0.00

    IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139.

  • CVE-2023-23348MedJul 10, 2023
    risk 0.33cvss 5.1epss 0.00

    HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.

  • CVE-2022-43877MedMay 6, 2023
    risk 0.33cvss 5.1epss 0.00

    IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file. IBM X-Force ID: 240148.

  • CVE-2021-42718MedJan 23, 2025
    risk 0.32cvss 4.9epss 0.00

    Information Disclosure in API in Replicated Replicated Classic versions prior to 2.53.1 on all platforms allows authenticated users with Admin Console access to retrieve sensitive data, including application secrets, via accessing container definitions with environment variables…

  • CVE-2024-10041MedOct 23, 2024
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain…

  • CVE-2024-36788MedJun 7, 2024
    risk 0.31cvss 4.8epss 0.00

    Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.