VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 15 of 20
  • CVE-2023-6748MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it possible for authenticated attackers with contributor access and above, to extract sensitive data…

  • CVE-2024-33004MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited…

  • CVE-2024-23561MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

  • CVE-2024-31278MedApr 10, 2024
    risk 0.28cvss 4.3epss 0.01

    Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.22.

  • CVE-2024-21826MedMar 4, 2024
    risk 0.28cvss 4.3epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

  • CVE-2023-34056MedOct 25, 2023
    risk 0.28cvss 4.3epss 0.01

    vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.

  • CVE-2021-36127MedJul 2, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppressed accounts (which are…

  • CVE-2020-4674MedJan 12, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-Force ID: 186287.

  • CVE-2020-4673MedJan 12, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.

  • CVE-2020-26176MedDec 18, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document//attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective…

  • CVE-2020-4315MedSep 21, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie…

  • CVE-2020-4171MedAug 27, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174407.

  • CVE-2019-12825MedFeb 17, 2020
    risk 0.28cvss 4.3epss 0.01

    Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not…

  • CVE-2019-13719MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.

  • CVE-2019-13717MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.

  • CVE-2017-16560MedNov 16, 2017
    risk 0.28cvss 4.3epss 0.00

    SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes.

  • CVE-2026-22251MedJan 12, 2026
    risk 0.27cvss 5.3epss 0.00

    wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

  • CVE-2025-2440MedApr 9, 2025
    risk 0.27cvss 4.2epss 0.00

    CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on the file system, sets the radio in factory default mode.

  • CVE-2025-20886MedFeb 4, 2025
    risk 0.27cvss 4.1epss 0.00

    Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.

  • CVE-2024-4213MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.01

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order…