Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-01-12 CVE-2020-4673 Insecure Storage of Sensitive Information vulnerability in IBM Workload Automation 9.5
IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system.
network
low complexity
ibm CWE-922
4.0
2020-12-24 CVE-2020-9202 Insecure Storage of Sensitive Information vulnerability in Huawei TE Mobile V600R006C10/V600R006C10Spc100
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100.
local
low complexity
huawei CWE-922
2.1
2020-12-18 CVE-2020-26176 Insecure Storage of Sensitive Information vulnerability in Tangro Business Workflow
An issue was discovered in tangro Business Workflow before 1.18.1.
network
low complexity
tangro CWE-922
4.0
2020-12-16 CVE-2020-4906 Insecure Storage of Sensitive Information vulnerability in IBM Financial Transaction Manager for Multiplatform 3.2.4
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
2.1
2020-11-26 CVE-2020-27663 Insecure Storage of Sensitive Information vulnerability in Glpi-Project Glpi
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
network
low complexity
glpi-project CWE-922
4.0
2020-11-26 CVE-2020-27662 Insecure Storage of Sensitive Information vulnerability in Glpi-Project Glpi
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
network
low complexity
glpi-project CWE-922
4.0
2020-11-16 CVE-2019-19562 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 2.1
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.
local
low complexity
harman CWE-922
2.1
2020-11-16 CVE-2019-19561 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 1.5
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
local
low complexity
harman CWE-922
2.1
2020-11-16 CVE-2019-19560 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 1.5
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.
local
low complexity
harman CWE-922
2.1
2020-11-16 CVE-2019-19557 Insecure Storage of Sensitive Information vulnerability in Harman Hermes 1.0
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
local
low complexity
harman CWE-922
2.1