Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2020-11-26 CVE-2020-27663 Insecure Storage of Sensitive Information vulnerability in Glpi-Project Glpi
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
network
low complexity
glpi-project CWE-922
4.0
2020-11-26 CVE-2020-27662 Insecure Storage of Sensitive Information vulnerability in Glpi-Project Glpi
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
network
low complexity
glpi-project CWE-922
4.0
2020-11-16 CVE-2019-19562 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 2.1
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.
local
low complexity
harman CWE-922
2.1
2020-11-16 CVE-2019-19561 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 1.5
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
local
low complexity
harman CWE-922
2.1
2020-11-16 CVE-2019-19560 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 1.5
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.
local
low complexity
harman CWE-922
2.1
2020-11-16 CVE-2019-19557 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 1.0
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
local
low complexity
harman CWE-922
2.1
2020-11-13 CVE-2020-4886 Insecure Storage of Sensitive Information vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system.
local
low complexity
ibm CWE-922
2.1
2020-10-29 CVE-2020-11484 Insecure Storage of Sensitive Information vulnerability in Intel BMC Firmware 1.06.06/2.47
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmware in which an attacker with administrative privileges can obtain the hash of the BMC/IPMI user password, which may lead to information disclosure.
network
low complexity
intel CWE-922
4.0
2020-10-27 CVE-2019-8898 Insecure Storage of Sensitive Information vulnerability in Apple products
An information disclosure issue existed in the handling of the Storage Access API.
network
apple CWE-922
4.3
2020-10-27 CVE-2019-8799 Insecure Storage of Sensitive Information vulnerability in Apple products
This issue was resolved by replacing device names with a random identifier.
local
low complexity
apple CWE-922
2.1