Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-25402 Insecure Storage of Sensitive Information vulnerability in Samsung Notes 2.0.02.31/4.2.00.22
Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.
local
low complexity
samsung CWE-922
3.3
2021-06-11 CVE-2021-25404 Insecure Storage of Sensitive Information vulnerability in Samsung Smartthings Firmware
Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.
local
low complexity
samsung CWE-922
3.3
2021-06-07 CVE-2020-5008 Insecure Storage of Sensitive Information vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters.
network
low complexity
ibm CWE-922
5.3
2021-06-01 CVE-2021-20575 Insecure Storage of Sensitive Information vulnerability in IBM Application Gateway and Security Verify Access
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2021-05-24 CVE-2020-28911 Insecure Storage of Sensitive Information vulnerability in Nagios Fusion
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
network
low complexity
nagios CWE-922
6.5
2021-05-19 CVE-2020-4765 Insecure Storage of Sensitive Information vulnerability in IBM Cloud PAK for Multicloud Management
IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2021-05-14 CVE-2021-20391 Insecure Storage of Sensitive Information vulnerability in IBM Qradar User Behavior Analytics 1.0.0/4.1.0
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2021-03-19 CVE-2021-28653 Insecure Storage of Sensitive Information vulnerability in Westerndigital Armorlock
The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely.
network
low complexity
westerndigital CWE-922
6.5
2021-03-02 CVE-2020-4726 Insecure Storage of Sensitive Information vulnerability in IBM Cloud Application Performance Management 8.1.4
The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2021-02-10 CVE-2021-27170 Insecure Storage of Sensitive Information vulnerability in Fiberhome Hg6245D Firmware Rp2613
An issue was discovered on FiberHome HG6245D devices through RP2613.
network
low complexity
fiberhome CWE-922
critical
9.8