Cyber Resilience

CWE · MITRE source

CWE-312Cleartext Storage of Sensitive Information

Abstraction: Base · CVEs in our corpus: 847

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Last updated: 22 August 2026 14:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 5 mapping(s) from 5 framework(s): STIG oracle linux 8 1 (mostly) · STIG oracle linux 9 1 (mostly) · STIG rhel 8 1 (mostly) · ATT&CK 1 (mostly) · CAPEC 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A06:2025 Insecure Design.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-12 Cryptographic Key Establishment and Management
  • SC-28 Protection of Information at Rest
  • SC-38 Operations Security
  • CM-13 Data Action Mapping
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 4 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V14.2.8

NIST 800-53 r5 controls that address this weakness (7)AI-assisted

Control Title Family Why it addresses this CWE
SC-12Cryptographic Key Establishment and ManagementSCKey-management policy requires protected storage of key material, preventing cleartext storage of sensitive cryptographic keys.
SC-28Protection of Information at RestSCRequiring confidentiality protection for information at rest eliminates cleartext storage of sensitive data on persistent media.
SC-38Operations SecuritySCReduces cleartext storage of sensitive data when OPSEC identifies and mandates protection of key information artifacts.
CM-13Data Action MappingCMData action mapping can detect storage actions that leave sensitive information in cleartext.
CM-6Configuration SettingsCMConfiguration policies can mandate secure storage methods to avoid cleartext storage of sensitive information.
AT-3Role-based TrainingATTraining on secure data handling discourages cleartext storage of sensitive information.
MP-1Policy and ProceduresMPPolicy requires protection measures such as encryption for sensitive data stored on media, preventing cleartext exposure.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-26148 9.49.80.53442022-03-21
CVE-2023-50719 8.47.50.83552023-12-15
CVE-2019-0285 8.09.80.06612019-04-10
CVE-2020-5723 8.09.80.05892020-03-30
CVE-2001-1481 7.89.80.02902001-12-31
CVE-2023-31069 7.89.80.03622023-09-11
CVE-2008-0174 7.79.80.01962008-01-29
CVE-2014-5433 7.79.80.02062019-03-26
CVE-2019-19228 7.79.80.01902019-12-04
CVE-2019-9823 7.69.80.01572019-07-03
CVE-2019-9873 7.69.80.01562019-07-03
CVE-2011-4723 KEV 7.55.70.02982011-12-20
CVE-2018-18641 7.59.80.00932018-12-04
CVE-2019-11384 7.59.80.00992019-04-22
CVE-2019-13096 7.59.80.01142019-07-22
CVE-2021-36782 7.59.90.03232022-09-07
CVE-2020-15332 7.59.80.00892022-09-29
CVE-2017-5249 7.49.80.00692018-02-22
CVE-2017-5250 7.49.80.00692018-02-22
CVE-2018-18394 7.49.80.00712018-10-19
CVE-2019-18868 7.49.80.00842020-05-07
CVE-2021-29954 7.49.80.00642021-06-24
CVE-2025-34216 7.49.80.00762025-09-29
CVE-2023-33373 7.39.80.00422023-08-04
CVE-2025-342067.39.80.00512025-09-19