Falhas do tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

A aplicação armazena dados sensíveis (senhas, tokens, chaves, PII) em locais acessíveis sem proteção adequada — memória não criptografada, logs, cache, arquivos de configuração ou banco de dados sem cifra. Um atacante com acesso ao sistema de arquivos, memória ou backups consegue ler essas informações diretamente.

Exemplo

Uma app de e-commerce salva números de cartão de crédito em texto plano em um arquivo SQLite local no dispositivo móvel. Um usuário com acesso físico ao telefone, malware ou análise forense do aparelho consegue extrair os cartões intactos. Outro caso comum: API que registra em log toda requisição incluindo o Bearer token do usuário.

Como mitigar

Criptografe dados sensíveis em repouso (AES-256 para arquivos, TDE para BD). Nunca armazene senhas — use hash + salt (PBKDF2, bcrypt, Argon2). Remova dados sensíveis de logs e memória assim que desnecessários. Para mobile, use Keychain (iOS) ou Keystore (Android). Revise configurações, backups e caches periodicamente.

CVE-2026-47362MEDIUMIn versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LEPSS 0.2%CVE-2024-37144HIGHDell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x tEPSS 0.2%CVE-2025-21098MEDIUMLiteos-A has an insecure storage of sensitive information vulnerabilityEPSS 0.2%CVE-2023-43634HIGH Config Partition Not Protected by Measured BootEPSS 0.2%CVE-2023-43633HIGHDebug Functions Unlockable Without Triggering Measured BootEPSS 0.2%CVE-2023-43631HIGHSSH as Root Unlockable Without Triggering Measured BootEPSS 0.2%CVE-2023-29261MEDIUMIBM Sterling Secure Proxy information disclosureEPSS 0.2%CVE-2022-43475MEDIUMInsecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2024-28132MEDIUMBIG-IP NEXT CNF vulnerability EPSS 0.2%CVE-2023-23437LOW Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak EPSS 0.2%CVE-2025-2489MEDIUMInsecure storage of sensitive information in NTFS ToolEPSS 0.2%CVE-2025-22492MEDIUMInsecure storage of connection strings in FRSEPSS 0.2%CVE-2026-77875MEDIUMHide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storageEPSS 0.2%CVE-2024-20462MEDIUMCisco ATA 190 Series Analog Telephone Adapter Muliplatform Firmware Information Disclosure VulnerabilityEPSS 0.2%CVE-2023-23348MEDIUMHCL Launch is vulnerable to sensitive information disclosureEPSS 0.2%CVE-2025-2157LOWForeman: disclosure of executed commands and outputs in foreman / red hat satelliteEPSS 0.2%CVE-2024-35311LOWYubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 havEPSS 0.2%CVE-2024-39612MEDIUMBackground Task Manager has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2024-38382MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2024-12082MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%