Cyber Posture

CWE · MITRE source

CWE-922Insecure Storage of Sensitive Information

Abstraction: Class · CVEs in our corpus: 368

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (8)AI

Control Title Family Why it addresses this CWE
CP-6Alternate Storage SiteCPEstablishing an alternate site with equivalent protections directly mitigates insecure storage of sensitive backup information.
CP-9System BackupCPRequiring protection of backup information directly addresses insecure storage of sensitive data in backups.
CM-12Information LocationCMTracking information locations and access supports secure storage practices instead of insecure ones.
PM-17Protecting Controlled Unclassified Information on External SystemsPMPolicy explicitly addresses insecure storage of CUI on external systems, requiring compliant handling and protections.
RA-2Security CategorizationRAProper categorization drives selection of storage controls that keep sensitive information from being stored insecurely.
SC-28Protection of Information at RestSCThe control explicitly requires secure storage mechanisms for sensitive information, closing the insecure-storage weakness class.
SI-23Information FragmentationSIStoring information as fragments on distinct components is an architectural control that avoids insecure single-location storage of the complete sensitive data set.
SR-7Supply Chain Operations SecuritySROPSEC requirements improve handling and storage practices for sensitive supply-chain information.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-139376.75.30.93332020-10-19
CVE-2018-250315.74.30.80422022-03-11
CVE-2024-308963.49.10.25742024-11-21
CVE-2020-14932.95.50.30332020-08-17
CVE-2020-289112.66.50.21442021-05-24
CVE-2024-75692.49.60.07472024-08-13
CVE-2024-377282.37.50.13452024-09-10
CVE-2017-52492.09.80.00182018-02-22
CVE-2017-52502.09.80.00152018-02-22
CVE-2020-84812.09.80.00502020-04-29
CVE-2021-271702.09.80.00082021-02-10
CVE-2021-423712.09.80.00732021-11-08
CVE-2023-297272.09.80.00162023-05-30
CVE-2023-321912.09.90.00202024-10-16
CVE-2024-49952.09.80.00192024-12-18
CVE-2025-125392.010.00.00722025-11-11
CVE-2021-288131.99.60.00372021-09-10
CVE-2022-355131.97.50.06292022-09-07
CVE-2017-72531.88.80.00842017-03-30
CVE-2023-436301.88.80.00012023-09-20
CVE-2023-436311.88.80.00032023-09-21
CVE-2023-436331.88.80.00022023-09-21
CVE-2023-436341.88.80.00032023-09-21
CVE-2023-429131.88.80.00372024-03-28
CVE-2024-109431.89.10.00122024-11-12