Falhas do tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

A aplicação armazena dados sensíveis (senhas, tokens, chaves, PII) em locais acessíveis sem proteção adequada — memória não criptografada, logs, cache, arquivos de configuração ou banco de dados sem cifra. Um atacante com acesso ao sistema de arquivos, memória ou backups consegue ler essas informações diretamente.

Exemplo

Uma app de e-commerce salva números de cartão de crédito em texto plano em um arquivo SQLite local no dispositivo móvel. Um usuário com acesso físico ao telefone, malware ou análise forense do aparelho consegue extrair os cartões intactos. Outro caso comum: API que registra em log toda requisição incluindo o Bearer token do usuário.

Como mitigar

Criptografe dados sensíveis em repouso (AES-256 para arquivos, TDE para BD). Nunca armazene senhas — use hash + salt (PBKDF2, bcrypt, Argon2). Remova dados sensíveis de logs e memória assim que desnecessários. Para mobile, use Keychain (iOS) ou Keystore (Android). Revise configurações, backups e caches periodicamente.

CVE-2024-3334MEDIUMUSB Security Feature Bypass in Digital Guardian Windows Agent Prior to version 8.2.0EPSS 0.1%CVE-2024-47122MEDIUMInsecure Storage of Sensitive Information in goTenna ProEPSS 0.1%CVE-2025-61482HIGHImproper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root aEPSS 0.1%CVE-2025-37110MEDIUMSensitive Credential Information stored insecurely in System DatabaseEPSS 0.1%CVE-2024-43694MEDIUMgoTenna Pro ATAK Plugin Insecure Storage of Sensitive InformationEPSS 0.1%CVE-2025-14376HIGHVerve Asset Manager – Plaintext Storage VulnerabilitiesEPSS 0.1%CVE-2023-40093MEDIUMIn multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This couldEPSS 0.1%CVE-2025-42979MEDIUMInsecure Key & Secret Management vulnerability in SAP GUI for WindowsEPSS 0.1%CVE-2023-6460MEDIUMInformation leak in nodejs-firestoreEPSS 0.1%CVE-2026-20629MEDIUMA privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to acceEPSS 0.1%CVE-2025-10971HIGHInsecure Storage of Sensitive InformationEPSS 0.1%CVE-2024-0037LOWIn applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission cEPSS 0.1%CVE-2023-43630HIGHConfig Partition Not Measured From 2 FrontsEPSS 0.1%CVE-2026-7257MEDIUM** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firEPSS 0.1%CVE-2024-34721MEDIUMIn ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. EPSS 0.1%CVE-2026-44629HIGHImproper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E EPSS 0.1%CVE-2026-20705MEDIUMInsecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow informEPSS 0.1%CVE-2025-32746MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attackEPSS 0.1%CVE-2025-32751MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attackerEPSS 0.1%CVE-2024-20050MEDIUMIn flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with SysEPSS 0.1%