Detect Insecure Storage of Sensitive Information with Automated Static Analysis
Documented detection approaches include Automated Static Analysis; recorded impacts include Read Application Data, Read Files or Directories, Modify Application Data, and Modify Files or Directories; observed examples include CVE-2009-2272. Use these source-defined anchors to turn CWE-922 into implementation, review, and verification checks for the affected component.
CWE-922: Insecure Storage of Sensitive Information — MITRE CWE