← Back
CWE-922

373 CVEs • Abstraction: Class

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

JSON object

Loading...

CVEs (373)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Guardium Insights
Jun 17, 2026
Aug 27, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174407.
1Ibm
1Guardium Data Encryption
Jun 17, 2026
Aug 26, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 171926.
1Microsoft
3365 Apps
OfficeOutlook
Jun 17, 2026
Aug 17, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where the...Show more
An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this vulnerability, an attacker would have to attach a file as a link to an email. The email could then be shared with individuals that should not have access to the files, ignoring the default organizational setting. The security update addresses the vulnerability by correcting how Outlook handles file attachment links.Show less
1Ibm
1Verify Gateway
Jun 17, 2026
Jul 22, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Force ID: 179008.
1Abb
1Device Library Wizard
Jun 17, 2026
May 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data
1Abb
1800xa System
Jun 17, 2026
Apr 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphon...Show more
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, confidential data is written in an unprotected file. An attacker who successfully exploited this vulnerability could take full control of the computer.Show less
1Visam
2Vbase Editor
Vbase Web Remote
Jun 17, 2026
Apr 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decrypti...Show more
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass authentication of the HTML5 HMI web interface.Show less
1Easybuild Project
1Easybuild
Jun 17, 2026
Mar 19, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuild debug log files. Th...Show more
In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuild debug log files. This issue is fixed in EasyBuild v4.1.2, and in the `master`+ `develop` branches of the `easybuild-framework` repository.Show less
1Ibm
1Tivoli Netcool/omnibus
Jun 17, 2026
Mar 3, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174908.
1Totolink
1A3002ru Firmware
Nov 21, 2024
Feb 24, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current pas...Show more
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password. However, this JavaScript contains the current user’s password in plaintext.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Feb 17, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate u...Show more
Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.Show less
1Mfscripts
1Yetishare
Jun 17, 2026
Feb 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
1Ibm
1Maximo Anywhere
Jun 17, 2026
Oct 10, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.
1Ibm
1Security Directory Server
Jun 17, 2026
Oct 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951.
1Jetbrains
1Vim
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
4.4 MEDIUM· v3
4.9 MEDIUM· v2
In KeyStore, there is a possible storage of symmetric keys in the TEE instead of the strongbox due to a missing strongbox flag. This could lead to local information disclosure with System execution privileges needed. Use...Show more
In KeyStore, there is a possible storage of symmetric keys in the TEE instead of the strongbox due to a missing strongbox flag. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109769728Show less
1Belwith Keeler
1Hickory Smart
Jun 17, 2026
Aug 22, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to...Show more
An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for iOS, version 01.01.07 and prior versions.Show less
1Belwith Keeler
1Hickory Smart
Jun 17, 2026
Aug 22, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used...Show more
An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.Show less