Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2020-11-13 CVE-2020-4886 Insecure Storage of Sensitive Information vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system.
local
low complexity
ibm CWE-922
3.3
2020-11-09 CVE-2020-4650 Insecure Storage of Sensitive Information vulnerability in IBM Maximo Spatial Asset Management
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2020-10-27 CVE-2019-8790 Insecure Storage of Sensitive Information vulnerability in Apple Swift
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0.
local
low complexity
apple CWE-922
5.5
2020-10-19 CVE-2020-13937 Insecure Storage of Sensitive Information vulnerability in Apache Kylin
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
network
low complexity
apache CWE-922
5.3
2020-09-25 CVE-2020-26104 Insecure Storage of Sensitive Information vulnerability in Cpanel
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
network
low complexity
cpanel CWE-922
7.5
2020-09-21 CVE-2020-4315 Insecure Storage of Sensitive Information vulnerability in IBM Business Automation Content Analyzer on Cloud 1.0
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-922
4.3
2020-09-18 CVE-2020-15775 Insecure Storage of Sensitive Information vulnerability in Gradle Enterprise
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4.
network
low complexity
gradle CWE-922
7.5
2020-09-15 CVE-2020-4344 Insecure Storage of Sensitive Information vulnerability in IBM Tivoli Business Service Manager 6.2.0.0
IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2020-08-27 CVE-2020-4171 Insecure Storage of Sensitive Information vulnerability in IBM Security Guardium Insights 2.0.1
IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the system.
network
low complexity
ibm CWE-922
4.3
2020-08-26 CVE-2019-4695 Insecure Storage of Sensitive Information vulnerability in IBM Guardium Data Encryption 3.0.0.2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3