CWE-922: Insecure Storage of Sensitive Information
ClassIncomplete
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
View on MITREBack to CWE Lookup
Extended Description
If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific