CWE-312: Cleartext Storage of Sensitive Information
Cleartext Storage of Sensitive Information
Weakness ID: 312 (Weakness Base)
Status: Draft
Description
Description Summary
The application stores sensitive information in cleartext
within a resource that might be accessible to another control sphere, when the
information should be encrypted or otherwise protected.
Extended Description
Because the information is stored in cleartext, attackers could
potentially read it.