Falhas do tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

A aplicação armazena dados sensíveis (senhas, tokens, chaves, PII) em locais acessíveis sem proteção adequada — memória não criptografada, logs, cache, arquivos de configuração ou banco de dados sem cifra. Um atacante com acesso ao sistema de arquivos, memória ou backups consegue ler essas informações diretamente.

Exemplo

Uma app de e-commerce salva números de cartão de crédito em texto plano em um arquivo SQLite local no dispositivo móvel. Um usuário com acesso físico ao telefone, malware ou análise forense do aparelho consegue extrair os cartões intactos. Outro caso comum: API que registra em log toda requisição incluindo o Bearer token do usuário.

Como mitigar

Criptografe dados sensíveis em repouso (AES-256 para arquivos, TDE para BD). Nunca armazene senhas — use hash + salt (PBKDF2, bcrypt, Argon2). Remova dados sensíveis de logs e memória assim que desnecessários. Para mobile, use Keychain (iOS) ou Keystore (Android). Revise configurações, backups e caches periodicamente.

CVE-2021-42718MEDIUMSensitive data unnecessarily returned from authenticated APIEPSS 0.4%CVE-2024-23217LOWA privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3,EPSS 0.4%CVE-2024-48353HIGHYealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintexEPSS 0.4%CVE-2024-25360MEDIUMA hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafteEPSS 0.4%CVE-2022-30361MEDIUMOvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authenticatioEPSS 0.4%CVE-2022-32867LOWThis issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iEPSS 0.4%CVE-2026-33407HIGHWallos: SSRF via HTTP Proxy Environment VariableEPSS 0.4%CVE-2024-40813MEDIUMA lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attackerEPSS 0.4%CVE-2020-10368LOWCertain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "SpeEPSS 0.4%CVE-2024-28808LOWAn issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to acEPSS 0.4%CVE-2024-23561MEDIUMHCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerabilityEPSS 0.4%CVE-2024-42018HIGHAn issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved EPSS 0.4%CVE-2023-49515MEDIUMInsecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proxiEPSS 0.4%CVE-2024-55931MEDIUMToken stored in session storageEPSS 0.4%CVE-2025-25732MEDIUMIncorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.4EPSS 0.4%CVE-2024-53931CRITICALThe com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permEPSS 0.4%CVE-2024-53932CRITICALThe com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enableEPSS 0.4%CVE-2019-5633MEDIUMHickory Smart Lock Insecure Storage on iOSEPSS 0.4%CVE-2019-5632MEDIUMHickory Smart Lock Insecure Storage on AndroidEPSS 0.4%CVE-2019-5627LOWBlueCats Reveal iOS App Insecure StorageEPSS 0.4%