Fallos del tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

Ocorre quando dados sensíveis (senhas, tokens, chaves, dados pessoais) são armazenados sem proteção adequada — em texto plano, em cache, em arquivos acessíveis ou em memória não cifrada. Um atacante que ganha acesso ao sistema consegue recuperar essas informações diretamente, comprometendo contas, autenticação e privacidade.

Ejemplo

Uma aplicação móvel salva o token de autenticação em SharedPreferences (Android) ou UserDefaults (iOS) sem encriptação; ou um servidor escreve senhas em arquivos de log; ou credenciais ficam em variáveis de ambiente em histórico de shell — tudo recuperável por quem tiver acesso ao dispositivo ou servidor.

Cómo mitigar

Use APIs de armazenamento seguro: Keychain (iOS), Keystore (Android), DPAPI (Windows), ou cofres de secrets (Vault, AWS Secrets Manager). Nunca registre dados sensíveis em logs. Cifre dados em repouso com padrões reconhecidos (AES-256) e remova do histórico e cache tudo que não for necessário manter.

CVE-2026-47362MEDIUMIn versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LEPSS 0.2%CVE-2024-37144HIGHDell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x tEPSS 0.2%CVE-2025-21098MEDIUMLiteos-A has an insecure storage of sensitive information vulnerabilityEPSS 0.2%CVE-2023-43634HIGH Config Partition Not Protected by Measured BootEPSS 0.2%CVE-2023-43633HIGHDebug Functions Unlockable Without Triggering Measured BootEPSS 0.2%CVE-2023-43631HIGHSSH as Root Unlockable Without Triggering Measured BootEPSS 0.2%CVE-2023-29261MEDIUMIBM Sterling Secure Proxy information disclosureEPSS 0.2%CVE-2022-43475MEDIUMInsecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2024-28132MEDIUMBIG-IP NEXT CNF vulnerability EPSS 0.2%CVE-2023-23437LOW Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak EPSS 0.2%CVE-2025-2489MEDIUMInsecure storage of sensitive information in NTFS ToolEPSS 0.2%CVE-2025-22492MEDIUMInsecure storage of connection strings in FRSEPSS 0.2%CVE-2026-77875MEDIUMHide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storageEPSS 0.2%CVE-2024-20462MEDIUMCisco ATA 190 Series Analog Telephone Adapter Muliplatform Firmware Information Disclosure VulnerabilityEPSS 0.2%CVE-2023-23348MEDIUMHCL Launch is vulnerable to sensitive information disclosureEPSS 0.2%CVE-2025-2157LOWForeman: disclosure of executed commands and outputs in foreman / red hat satelliteEPSS 0.2%CVE-2024-35311LOWYubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 havEPSS 0.2%CVE-2024-39612MEDIUMBackground Task Manager has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2024-38382MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2024-12082MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%