CWE-921Base

Storage of Sensitive Data in a Mechanism without Access Control

Incomplete in the CWE catalog · 9 CVEs mapped

9
CVEs mapped
6.0
Median CVSS
What it is

The product stores sensitive information in a file system or device that does not have built-in access control.

Recent examples
9.8cvss
CVE-2025-30016

Authentication Bypass Vulnerability in SAP Financial Consolidation

🚨 A misconfigured authentication system in SAP Financial Consolidation is the key to an open door—anyone could access the Admin account without a password! 🔥 Think of it like a five-star restaurant where the front door is wide open, and the host isn't even checking who walks in—everyone's welcome to the VIP kitchen without a reservation! An attacker could stroll in and wreak havoc—alter financial records, expose sensitive data, or even disrupt operations entirely. With the integrity and confidentiality of your financial data at stake, this vulnerability poses an absolutely devastating threat to your organization!

CRITICAL
1%
epss
5.1cvss
CVE-2025-24843

Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Storage of Sensitive Data in a Mechanism without Access Control

Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.

MEDIUMno explanation yet
0%
epss
8.2cvss
CVE-2024-9334

Information Disclosure in E-Kent's Pallium Vehicle Tracking

Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass. This issue affects Pallium Vehicle Tracking: before 17.10.2024.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-921
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)