CWE-922
Overview
- CWE ID
- 922
- CWE Name
- Insecure Storage of Sensitive Information
- CWE Abstraction
- Class
- CWE structure
- Simple
- CWE Status
- Incomplete
Description
The software stores sensitive information without properly limiting read or write access by unauthorized actors.
Extended Description
If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.
Related CWEs
CWE ID | View ID | Nature | Ordinal |
---|---|---|---|
664 | 1000 | ChildOf | Primary |