← Back
CWE-922

373 CVEs • Abstraction: Class

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

JSON object

Loading...

CVEs (373)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Cloud Application Performance Management
Jun 17, 2026
Mar 2, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.
1Fiberhome
1Hg6245d Firmware
Jun 17, 2026
Feb 10, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
1Mantisbt
1Mantisbt
Jun 17, 2026
Jan 29, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.
1Ibm
1Planning Analytics
Jun 17, 2026
Jan 19, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.
1Ibm
1Workload Automation
Jun 17, 2026
Jan 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-Force ID: 186287.
1Ibm
1Workload Automation
Jun 17, 2026
Jan 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.
1Huawei
1Te Mobile
Jun 17, 2026
Dec 24, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain informati...Show more
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain information in the victim's device to launch the attack, successful exploit could cause information disclosure.Show less
1Tangro
1Business Workflow
Jun 17, 2026
Dec 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all th...Show more
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.Show less
1Ibm
1Financial Transaction Manager For Multiplatform
Jun 17, 2026
Dec 16, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.
1Harman
1Hermes
Jun 17, 2026
Nov 16, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
1Harman
1Hermes
Jun 17, 2026
Nov 16, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 13, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.
1Ibm
1Maximo Spatial Asset Management
Jun 17, 2026
Nov 9, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.
1Apple
1Swift
Jun 17, 2026
Oct 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could...Show more
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.Show less
1Apache
1Kylin
Jun 17, 2026
Oct 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha ha...Show more
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.Show less
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
1Ibm
1Business Automation Content Analyzer On Cloud
Jun 17, 2026
Sep 21, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by...Show more
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 177234.Show less
1Gradle
1Enterprise
Jun 17, 2026
Sep 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewabl...Show more
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.Show less
1Ibm
1Tivoli Business Service Manager
Jun 17, 2026
Sep 15, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.