Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-06-16 CVE-2021-22914 Insecure Storage of Sensitive Information vulnerability in Citrix Cloud Connector
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files.
network
low complexity
citrix CWE-922
5.0
2021-06-16 CVE-2021-28815 Insecure Storage of Sensitive Information vulnerability in Qnap Myqnapcloud Link
Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link.
network
low complexity
qnap CWE-922
4.0
2021-06-11 CVE-2021-20396 Insecure Storage of Sensitive Information vulnerability in IBM Security Qradar Analyst Workflow
IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
2.1
2021-06-11 CVE-2021-25402 Insecure Storage of Sensitive Information vulnerability in Samsung Notes 2.0.02.31/4.2.00.22
Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.
local
low complexity
samsung CWE-922
2.1
2021-06-11 CVE-2021-25404 Insecure Storage of Sensitive Information vulnerability in Samsung Smartthings Firmware
Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.
local
low complexity
samsung CWE-922
2.1
2021-06-07 CVE-2020-5008 Insecure Storage of Sensitive Information vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters.
network
low complexity
ibm CWE-922
5.0
2021-06-01 CVE-2021-20575 Insecure Storage of Sensitive Information vulnerability in IBM Application Gateway and Security Verify Access
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
2.1
2021-05-24 CVE-2020-28911 Insecure Storage of Sensitive Information vulnerability in Nagios Fusion
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
network
low complexity
nagios CWE-922
4.0
2021-05-19 CVE-2020-4765 Insecure Storage of Sensitive Information vulnerability in IBM Cloud PAK for Multicloud Management
IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
2.1
2021-05-14 CVE-2021-20391 Insecure Storage of Sensitive Information vulnerability in IBM Qradar User Behavior Analytics 1.0.0/4.1.0
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
2.1