Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2023-09-05 CVE-2023-29261 Insecure Storage of Sensitive Information vulnerability in IBM Sterling External Authentication Server 6.0.3.0/6.1.0
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations.
local
low complexity
ibm CWE-922
5.5
2023-08-02 CVE-2022-46484 Insecure Storage of Sensitive Information vulnerability in Ngsurvey 2.4.28
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
network
low complexity
ngsurvey CWE-922
7.5
2023-07-17 CVE-2023-28864 Insecure Storage of Sensitive Information vulnerability in Progress Chef Infra Server
Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed.
local
low complexity
progress CWE-922
5.5
2023-06-05 CVE-2023-3064 Insecure Storage of Sensitive Information vulnerability in Mobatime Amxgt 100
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
network
low complexity
mobatime CWE-922
5.3
2023-05-12 CVE-2023-2665 Insecure Storage of Sensitive Information vulnerability in Rosariosis
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.
network
low complexity
rosariosis CWE-922
7.5
2023-05-10 CVE-2023-31150 Insecure Storage of Sensitive Information vulnerability in Selinc products
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-922
6.5
2023-05-10 CVE-2022-43475 Insecure Storage of Sensitive Information vulnerability in Intel Data Center Manager
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-922
7.8
2023-05-10 CVE-2022-44619 Insecure Storage of Sensitive Information vulnerability in Intel Data Center Manager
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-922
7.8
2023-05-06 CVE-2022-43877 Insecure Storage of Sensitive Information vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file.
local
low complexity
ibm CWE-922
5.5
2023-04-16 CVE-2023-22687 Insecure Storage of Sensitive Information vulnerability in Freesoul Deactivate Plugins - Plugin Manager and Cleanup Project Freesoul Deactivate Plugins - Plugin Manager and Cleanup
Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup plugin <= 1.9.4.0 versions.
7.5