VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 9 of 20
  • CVE-2023-37439MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.00

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2025-37110MedJul 31, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.

  • CVE-2023-52345MedApr 8, 2024
    risk 0.39cvss 6.0epss 0.00

    In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

  • CVE-2023-6253MedNov 22, 2023
    risk 0.39cvss 6.0epss 0.00

    A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

  • CVE-2022-43475MedMay 10, 2023
    risk 0.39cvss 6.0epss 0.00

    Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-38090MedFeb 16, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2021-28815MedJun 16, 2021
    risk 0.39cvss 6.0epss 0.02

    Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc.…

  • CVE-2024-44213MedOct 28, 2024
    risk 0.38cvss 5.9epss 0.01

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker in a privileged network position may be able to leak sensitive user information.

  • CVE-2024-30122MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.

  • CVE-2024-46635MedSep 30, 2024
    risk 0.38cvss 5.9epss 0.00

    An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.

  • CVE-2024-6916MedJul 19, 2024
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

  • CVE-2024-29120MedJul 17, 2024
    risk 0.38cvss 5.9epss 0.00

    In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password,…

  • CVE-2024-35526MedJun 25, 2024
    risk 0.38cvss 5.9epss 0.00

    An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.

  • CVE-2019-3684MedMay 13, 2019
    risk 0.38cvss 5.9epss 0.01

    SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem

  • CVE-2024-51399MedNov 1, 2024
    risk 0.37cvss 5.7epss 0.00

    Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can lead to data breaches…

  • CVE-2026-5515MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2025-32751MedMay 22, 2026
    risk 0.36cvss 5.5epss 0.00

    Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.

  • CVE-2026-20629MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.

  • CVE-2025-42979MedJul 8, 2025
    risk 0.36cvss 5.6epss 0.00

    The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access…

  • CVE-2025-21098MedMar 4, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.