VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (383)

page 18 of 20
  • CVE-2023-23541LowMay 8, 2023
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to access information about a user’s contacts.

  • CVE-2022-33973LowNov 11, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-4809LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189633.

  • CVE-2020-4805LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189539.

  • CVE-2020-4803LowSep 23, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189535.

  • CVE-2021-25404LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.

  • CVE-2021-25402LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.

  • CVE-2021-20396LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 196009.

  • CVE-2021-20575LowJun 1, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.

  • CVE-2020-4765LowMay 19, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.

  • CVE-2021-20391LowMay 14, 2021
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.

  • CVE-2020-4726LowMar 2, 2021
    risk 0.21cvss 3.3epss 0.00

    The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.

  • CVE-2020-29603MedJan 29, 2021
    risk 0.21cvss 4.3epss 0.01

    In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.

  • CVE-2020-4906LowDec 16, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2020-4886LowNov 13, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.

  • CVE-2020-4650LowNov 9, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.

  • CVE-2020-4344LowSep 15, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.

  • CVE-2019-4695LowAug 26, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 171926.

  • CVE-2020-4371LowJul 22, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Force ID: 179008.

  • CVE-2024-22371LowFeb 26, 2024
    risk 0.19cvss 2.9epss 0.01

    Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through…