VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 4 of 20
  • CVE-2024-22808HigApr 22, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the card's name in the device memory.

  • CVE-2024-28069HigMar 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive…

  • CVE-2024-1936HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.01

    The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a…

  • CVE-2024-25728HigFeb 11, 2024
    risk 0.49cvss 7.5epss 0.01

    ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain…

  • CVE-2023-41965HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.

  • CVE-2022-46484HigAug 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.

  • CVE-2023-3064HigJun 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.

  • CVE-2021-36546HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.

  • CVE-2022-41876HigNov 10, 2022
    risk 0.49cvss 7.5epss 0.01

    ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that…

  • CVE-2022-37835HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges.

  • CVE-2022-28168HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.

  • CVE-2022-25264HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

  • CVE-2021-36786HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.

  • CVE-2021-22914HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud…

  • CVE-2021-25776HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.

  • CVE-2020-26104HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).

  • CVE-2020-15775HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.

  • CVE-2020-7000HigApr 3, 2020
    risk 0.49cvss 7.5epss 0.01

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass…

  • CVE-2019-20060HigFeb 10, 2020
    risk 0.49cvss 7.5epss 0.01

    MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.

  • CVE-2019-12914HigJul 17, 2019
    risk 0.49cvss 7.5epss 0.01

    Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.