Weaknesses of type CWE-316

41 results

Armazenamento de informações sensíveis em texto claro na memória

O aplicativo mantém dados sensíveis (senhas, tokens, chaves criptográficas) desprotegidos na RAM enquanto está em execução. Qualquer processo com acesso à memória — via dump de heap, debugger ou exploit — consegue ler essas informações diretamente, comprometendo a confidencialidade.

Example

Uma aplicação Java carrega uma senha do banco de dados em uma String e a mantém lá durante toda a sessão. Um ataque de information disclosure ou uma análise pós-crash via coredump revela a senha em texto claro. Ideal seria usar char[] e sobrescrever com zeros após o uso.

How to mitigate

Use estruturas que permitem limpeza explícita (char[] em Java, SecureString em .NET), sobrescreva dados sensíveis imediatamente após uso, implemente proteção de memória (ASLR, DEP) e limite acesso aos processos. Ferramentas como valgrind ajudam a detectar vazamentos.

CVE-2024-35282LOWA cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versiEPSS 0.2%CVE-2022-46141MEDIUMA vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allowEPSS 0.1%CVE-2025-65832MEDIUMThe mobile application insecurely handles information stored within memory. By performing a memory dump on the application after a user has EPSS 0.1%CVE-2024-9203LOWEnpass Password Manager sensitive information in memoryEPSS 0.1%CVE-2022-33918MEDIUMDell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user could potentially exploEPSS 0.1%CVE-2025-48930LOWThe TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to aEPSS 0.1%CVE-2023-40724HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attackeEPSS 0.1%CVE-2026-77407HIGHRabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct FieldsEPSS 0.1%CVE-2025-50109HIGHEmerson ValveLink Products Cleartext Storage of Sensitive Information in MemoryEPSS 0.1%CVE-2025-61713LOWA Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPEPSS 0.1%CVE-2025-42888MEDIUMInformation Disclosure vulnerability in SAP GUI for WindowsEPSS 0.1%CVE-2021-23211MEDIUMCleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption keyEPSS 0.1%CVE-2025-60791MEDIUMEasywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bouEPSS 0.1%CVE-2025-9970MEDIUMApplication credential stored in clear text in memoryEPSS 0.1%CVE-2026-24319MEDIUMInformation Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)EPSS 0.1%CVE-2026-75137MEDIUMUpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after LockEPSS 0.1%CVE-2026-75135MEDIUMUpSignOn < 7.19.0 Sensitive Key Retention in MemoryEPSS 0.1%CVE-2023-23349LOWKaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled crEPSS 0.1%CVE-2025-4618MEDIUMPrisma Browser: Sensitive Information Disclosure Vulnerability in Prisma BrowserEPSS 0.1%CVE-2026-27875MEDIUMSimplex Incident Manager Clear TestEPSS 0.1%