Weaknesses of type CWE-922

283 results

Armazenamento inseguro de informações sensíveis

É quando dados críticos (senhas, tokens, chaves criptográficas, PII) são guardados em local ou formato que qualquer pessoa com acesso ao sistema consegue ler. O risco: um atacante com acesso ao disco, memória ou arquivo de configuração rouba os dados sem esforço, comprometendo usuários e a aplicação inteira.

Example

Um app grava a senha do usuário em texto plano dentro de um arquivo .txt na raiz do projeto, ou armazena token de API em um cookie sem criptografia. Se o servidor for invadido ou o cliente roubado, as credenciais caem na mão de quem não deveria ter.

How to mitigate

Use criptografia forte (AES-256) para dados em repouso, aplique hash com salt (bcrypt, Argon2) em senhas, armazene segredos em vaults dedicados (AWS Secrets Manager, HashiCorp Vault), e nunca commita chaves ou credenciais no código. Revise regularmente o que é guardado e onde.

CVE-2026-47362MEDIUMIn versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LEPSS 0.2%CVE-2024-37144HIGHDell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x tEPSS 0.2%CVE-2025-21098MEDIUMLiteos-A has an insecure storage of sensitive information vulnerabilityEPSS 0.2%CVE-2023-43634HIGH Config Partition Not Protected by Measured BootEPSS 0.2%CVE-2023-43633HIGHDebug Functions Unlockable Without Triggering Measured BootEPSS 0.2%CVE-2023-43631HIGHSSH as Root Unlockable Without Triggering Measured BootEPSS 0.2%CVE-2023-29261MEDIUMIBM Sterling Secure Proxy information disclosureEPSS 0.2%CVE-2022-43475MEDIUMInsecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2024-28132MEDIUMBIG-IP NEXT CNF vulnerability EPSS 0.2%CVE-2023-23437LOW Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak EPSS 0.2%CVE-2025-2489MEDIUMInsecure storage of sensitive information in NTFS ToolEPSS 0.2%CVE-2025-22492MEDIUMInsecure storage of connection strings in FRSEPSS 0.2%CVE-2026-77875MEDIUMHide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storageEPSS 0.2%CVE-2024-20462MEDIUMCisco ATA 190 Series Analog Telephone Adapter Muliplatform Firmware Information Disclosure VulnerabilityEPSS 0.2%CVE-2023-23348MEDIUMHCL Launch is vulnerable to sensitive information disclosureEPSS 0.2%CVE-2025-2157LOWForeman: disclosure of executed commands and outputs in foreman / red hat satelliteEPSS 0.2%CVE-2024-35311LOWYubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 havEPSS 0.2%CVE-2024-39612MEDIUMBackground Task Manager has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2024-38382MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2024-12082MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%