VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 18 of 20
  • CVE-2020-4809LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189633.

  • CVE-2020-4805LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189539.

  • CVE-2020-4803LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189535.

  • CVE-2021-25404LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.

  • CVE-2021-25402LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.

  • CVE-2021-20396LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 196009.

  • CVE-2021-20575LowJun 1, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.

  • CVE-2020-4765LowMay 19, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.

  • CVE-2021-20391LowMay 14, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.

  • CVE-2020-4726LowMar 2, 2021
    risk 0.21cvss 3.3epss 0.00

    The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.

  • CVE-2020-29603MedJan 29, 2021
    risk 0.21cvss 4.3epss 0.01

    In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.

  • CVE-2020-4906LowDec 16, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2020-4886LowNov 13, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.

  • CVE-2020-4650LowNov 9, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.

  • CVE-2020-4344LowSep 15, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.

  • CVE-2019-4695LowAug 26, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 171926.

  • CVE-2020-4371LowJul 22, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Force ID: 179008.

  • CVE-2024-22371LowFeb 26, 2024
    risk 0.19cvss 2.9epss 0.01

    Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through…

  • CVE-2023-6460MedDec 4, 2023
    risk 0.19cvss 4.0epss 0.00

    A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version…

  • CVE-2024-28808LowSep 30, 2024
    risk 0.18cvss 2.7epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.