← Back
CWE-922

377 CVEs • Abstraction: Class

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

JSON object

Loading...

CVEs (377)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nagios
1Fusion
Jun 17, 2026
May 24, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
1Ibm
1Cloud Pak For Multicloud Management
Jun 17, 2026
May 19, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.
1Ibm
1Qradar User Behavior Analytics
Jun 17, 2026
May 14, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.
1Westerndigital
1Armorlock
Jun 17, 2026
Mar 19, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometri...Show more
The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometric authentication hardware.Show less
1Ibm
1Cloud Application Performance Management
Jun 17, 2026
Mar 2, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.
1Fiberhome
1Hg6245d Firmware
Jun 17, 2026
Feb 10, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
1Mantisbt
1Mantisbt
Jun 17, 2026
Jan 29, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.
1Ibm
1Planning Analytics
Jun 17, 2026
Jan 19, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.
1Ibm
1Workload Automation
Jun 17, 2026
Jan 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-Force ID: 186287.
1Ibm
1Workload Automation
Jun 17, 2026
Jan 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.
1Huawei
1Te Mobile
Jun 17, 2026
Dec 24, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain informati...Show more
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain information in the victim's device to launch the attack, successful exploit could cause information disclosure.Show less
1Tangro
1Business Workflow
Jun 17, 2026
Dec 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all th...Show more
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.Show less
1Ibm
1Financial Transaction Manager For Multiplatform
Jun 17, 2026
Dec 16, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.
1Harman
1Hermes
Jun 17, 2026
Nov 16, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
1Harman
1Hermes
Jun 17, 2026
Nov 16, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 13, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.
1Ibm
1Maximo Spatial Asset Management
Jun 17, 2026
Nov 9, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.
1Apple
1Swift
Jun 17, 2026
Oct 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could...Show more
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.Show less
1Apache
1Kylin
Jun 17, 2026
Oct 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha ha...Show more
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.Show less