CWE · MITRE source
CWE-922Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 3 mapping(s) from 2 framework(s): STIG windows server 2016 2 (partial) · STIG windows server 2019 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 3 hardening rules · 2 OS baselines
—
NIST 800-53 r5 controls that address this weakness (8)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
CP-6 | Alternate Storage Site | CP | Establishing an alternate site with equivalent protections directly mitigates insecure storage of sensitive backup information. |
CP-9 | System Backup | CP | Requiring protection of backup information directly addresses insecure storage of sensitive data in backups. |
CM-12 | Information Location | CM | Tracking information locations and access supports secure storage practices instead of insecure ones. |
PM-17 | Protecting Controlled Unclassified Information on External Systems | PM | Policy explicitly addresses insecure storage of CUI on external systems, requiring compliant handling and protections. |
RA-2 | Security Categorization | RA | Proper categorization drives selection of storage controls that keep sensitive information from being stored insecurely. |
SC-28 | Protection of Information at Rest | SC | The control explicitly requires secure storage mechanisms for sensitive information, closing the insecure-storage weakness class. |
SI-23 | Information Fragmentation | SI | Storing information as fragments on distinct components is an architectural control that avoids insecure single-location storage of the complete sensitive data set. |
SR-7 | Supply Chain Operations Security | SR | OPSEC requirements improve handling and storage practices for sensitive supply-chain information. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2021-27170 UPD | 8.4 | 9.8 | 0.1595 | 2021-02-10 |
CVE-2020-8481 UPD | 7.6 | 9.8 | 0.0181 | 2020-04-29 |
CVE-2021-42371 UPD | 7.6 | 9.8 | 0.0151 | 2021-11-08 |
CVE-2025-12539 UPD | 7.6 | 10.0 | 0.0106 | 2025-11-11 |
CVE-2023-29727 UPD | 7.5 | 9.8 | 0.0121 | 2023-05-30 |
CVE-2024-4995 UPD | 7.5 | 9.8 | 0.0093 | 2024-12-18 |
CVE-2017-5249 UPD | 7.4 | 9.8 | 0.0069 | 2018-02-22 |
CVE-2017-5250 UPD | 7.4 | 9.8 | 0.0069 | 2018-02-22 |
CVE-2024-7569 UPD | 7.1 | 9.6 | 0.0174 | 2024-08-13 |
CVE-2017-7253 UPD | 7.0 | 8.8 | 0.0259 | 2017-03-30 |
CVE-2020-13937 UPD | 7.0 | 5.3 | 0.7833 | 2020-10-19 |
CVE-2021-28813 UPD | 7.0 | 9.6 | 0.0109 | 2021-09-10 |
CVE-2023-32191 UPD | 7.0 | 9.9 | 0.0066 | 2024-10-16 |
CVE-2024-30896 UPD | 7.0 | 9.1 | 0.0521 | 2024-11-21 |
CVE-2025-8699 UPD | 7.0 | 9.1 | 0.0074 | 2025-09-12 |
CVE-2024-10943 UPD | 6.9 | 9.1 | 0.0048 | 2024-11-12 |
CVE-2024-53931 UPD | 6.8 | 9.1 | 0.0035 | 2025-01-06 |
CVE-2024-53932 UPD | 6.8 | 9.1 | 0.0035 | 2025-01-06 |
CVE-2026-33407 | 6.8 | 9.1 | 0.0037 | 2026-03-24 |
CVE-2023-42913 UPD | 6.6 | 8.8 | 0.0054 | 2024-03-28 |
CVE-2025-28244 UPD | 6.6 | 8.8 | 0.0045 | 2025-07-10 |
CVE-2022-35513 UPD | 6.5 | 7.5 | 0.0464 | 2022-09-07 |
CVE-2024-22773 UPD | 6.3 | 8.1 | 0.0097 | 2024-02-06 |
CVE-2023-50298 UPD | 6.2 | 7.5 | 0.0156 | 2024-02-09 |
CVE-2024-37728 UPD | 6.2 | 7.5 | 0.0185 | 2024-09-10 |