Common Weakness Enumeration

    CWE Definition / CWE-212

    CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer

    The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:30 Apr 2026

    Related Weakness

    CWE-669: Incorrect Resource Transfer Between Spheres

    CWE-669: Incorrect Resource Transfer Between Spheres

    CWE-201: Insertion of Sensitive Information Into Sent Data