CWE-922

Insecure Storage of Sensitive Information

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

373 vulnerabilities with CWE-922
CVE-2019-13717 MEDIUM
Google Chrome < 78.0.3904.70 - Insecure Storage of Sensitive Information via Full Screen Mode
CVSS 4.3
CVE-2019-4265 LOW
IBM Maximo Anywhere <7.6.4 - Info Disclosure
CVSS 2.4
CVE-2019-4549 MEDIUM
IBM Security Directory Server 6.4.0 - Info Disclosure
CVSS 5.3
CVE-2019-14957 MEDIUM
JetBrains Vim <0.52 - Info Disclosure
CVSS 5.3
CVE-2019-9253 MEDIUM
Android 10 - Insecure Storage of Sensitive Information in KeyStore
CVSS 4.4
CVE-2019-5633 MEDIUM
Hickory Smart <1.01.07 - Info Disclosure
CVSS 5.5
CVE-2019-5632 MEDIUM
Hickory Smart <1.01.43 - Info Disclosure
CVSS 5.5
CVE-2019-12914 HIGH
Redbrick Shift <3.4.3 - Info Disclosure
CVSS 7.5
CVE-2019-12911 HIGH
Redbrick Shift <3.4.3 - Info Disclosure
CVSS 7.5
CVE-2019-5627 HIGH
BlueCats bc_reveal < 5.14 - Insufficiently Protected Credentials in App Cache
CVSS 7.8
CVE-2019-5626 HIGH
BlueCats Reveal < 3.0.19 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2019-5625 HIGH
Eaton Halo Home < 1.11.0 - Insufficiently Protected Credentials
CVSS 7.1
CVE-2019-3684 MEDIUM
SUSE Manager <4.0.7 - Info Disclosure
CVSS 5.9
CVE-2018-25031 MEDIUM
Swagger UI < 4.1.3 - Server-Side Request Forgery via OpenAPI Definition URL
CVSS 4.3
CVE-2018-13313 MEDIUM
TOTOLINK A3002RU 1.0.8 - Info Disclosure
CVSS 6.5
CVE-2018-20886 MEDIUM
cPanel < 70.0.53 - Insecure Storage of Sensitive Information in phpMyAdmin Session Files
CVSS 5.3
CVE-2017-13909 MEDIUM
macOS High Sierra <10.13 - Info Disclosure
CVSS 5.5
CVE-2017-5250 CRITICAL
Insteon for Hub <1.9.7 - Info Disclosure
CVSS 9.8
CVE-2017-5249 CRITICAL
Wink Labs' Wink <6.1.0.19 - Info Disclosure
CVSS 9.8
CVE-2017-16560 MEDIUM
SanDisk Secure Access <3.01 - Info Disclosure
CVSS 4.3
CVE-2017-0493 MEDIUM
Android 7.0-7.1.1 - Local Lock Screen Bypass via File-Based Encryption
CVSS 5.5
CVE-2017-7253 HIGH
Dahua IP Camera <3.200.0001.6 - Info Disclosure
CVSS 8.8
CVE-2017-6911 MEDIUM
USB Pratirodh - Insecure Storage of Sensitive Information in usb.xml
CVSS 6.6
Details
Vulnerabilities 373