Falhas do tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

A aplicação armazena dados sensíveis (senhas, tokens, chaves, PII) em locais acessíveis sem proteção adequada — memória não criptografada, logs, cache, arquivos de configuração ou banco de dados sem cifra. Um atacante com acesso ao sistema de arquivos, memória ou backups consegue ler essas informações diretamente.

Exemplo

Uma app de e-commerce salva números de cartão de crédito em texto plano em um arquivo SQLite local no dispositivo móvel. Um usuário com acesso físico ao telefone, malware ou análise forense do aparelho consegue extrair os cartões intactos. Outro caso comum: API que registra em log toda requisição incluindo o Bearer token do usuário.

Como mitigar

Criptografe dados sensíveis em repouso (AES-256 para arquivos, TDE para BD). Nunca armazene senhas — use hash + salt (PBKDF2, bcrypt, Argon2). Remova dados sensíveis de logs e memória assim que desnecessários. Para mobile, use Keychain (iOS) ou Keystore (Android). Revise configurações, backups e caches periodicamente.

CVE-2024-54504MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2. An app may beEPSS 0.2%CVE-2024-48883MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200,EPSS 0.2%CVE-2024-54541MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS SonomEPSS 0.2%CVE-2025-54083MEDIUMCalix GigaCenter ONT firmware - Sensitive Information DisclosureEPSS 0.2%CVE-2022-44619HIGHInsecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2023-40728HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensEPSS 0.2%CVE-2023-42839MEDIUMThis issue was addressed with improved state management. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPaEPSS 0.2%CVE-2024-21826MEDIUMHuks has an insecure storage of sensitive information vulnerabilityEPSS 0.2%CVE-2025-11645LOWTomofun Furbo Mobile App Authentication Token sensitive informationEPSS 0.2%CVE-2022-34354MEDIUMIBM Sterling Partner Engagement Manager information disclosureEPSS 0.2%CVE-2024-44174MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An attacker may be able to view restricted content frEPSS 0.2%CVE-2024-54549MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2. An app may be able to EPSS 0.2%CVE-2024-44200MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15EPSS 0.2%CVE-2024-44292MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may beEPSS 0.2%CVE-2025-2440MEDIUMCWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential dEPSS 0.2%CVE-2022-43877MEDIUMIBM UrbanCode Deploy (UCD) information disclosureEPSS 0.2%CVE-2023-42878MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, EPSS 0.2%CVE-2025-59320MEDIUMCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthentEPSS 0.2%CVE-2022-33973LOWImproper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user EPSS 0.2%CVE-2023-37540LOWHCL Sametime Chat is affected by an unimplemented feature in the UI EPSS 0.2%