VYPR

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

ClassDraftLikelihood: High

Description

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-116 · CAPEC-13 · CAPEC-169 · CAPEC-22 · CAPEC-224 · CAPEC-285 · CAPEC-287 · CAPEC-290 · CAPEC-291 · CAPEC-292 · CAPEC-293 · CAPEC-294 · CAPEC-295 · CAPEC-296 · CAPEC-297 · CAPEC-298 · CAPEC-299 · CAPEC-300 · CAPEC-301 · CAPEC-302 · CAPEC-303 · CAPEC-304 · CAPEC-305 · CAPEC-306 · CAPEC-307 · CAPEC-308 · CAPEC-309 · CAPEC-310 · CAPEC-312 · CAPEC-313 · CAPEC-317 · CAPEC-318 · CAPEC-319 · CAPEC-320 · CAPEC-321 · CAPEC-322 · CAPEC-323 · CAPEC-324 · CAPEC-325 · CAPEC-326 · CAPEC-327 · CAPEC-328 · CAPEC-329 · CAPEC-330 · CAPEC-472 · CAPEC-497 · CAPEC-508 · CAPEC-573 · CAPEC-574 · CAPEC-575 · CAPEC-576 · CAPEC-577 · CAPEC-59 · CAPEC-60 · CAPEC-616 · CAPEC-643 · CAPEC-646 · CAPEC-651 · CAPEC-79

CVEs mapped to this weakness (5,448)

page 108 of 273
  • CVE-2016-4947MedMar 7, 2017
    risk 0.34cvss 5.3epss 0.00

    Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.

  • CVE-2016-4042MedFeb 24, 2017
    risk 0.34cvss 5.3epss 0.00

    Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.

  • CVE-2017-3842MedFeb 22, 2017
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455. Known Affected Releases: 7.2(1)V7.

  • CVE-2017-6072MedFeb 21, 2017
    risk 0.34cvss 5.3epss 0.00

    CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.

  • CVE-2017-6071MedFeb 21, 2017
    risk 0.34cvss 5.3epss 0.00

    CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.

  • CVE-2016-6249MedFeb 20, 2017
    risk 0.34cvss 5.3epss 0.00

    F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.

  • CVE-2016-5813MedFeb 13, 2017
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. When a specific URL to an image is accessed, the downloaded image carries with it source code used in the web server (INFORMATION EXPOSURE).

  • CVE-2016-0210MedFeb 8, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.

  • CVE-2016-3124MedFeb 7, 2017
    risk 0.34cvss 5.3epss 0.00

    The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.

  • CVE-2016-9772MedFeb 6, 2017
    risk 0.34cvss 5.3epss 0.00

    OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.

  • CVE-2016-6099MedFeb 2, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.

  • CVE-2016-8982MedFeb 1, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.

  • CVE-2016-8977MedFeb 1, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.

  • CVE-2016-6117MedFeb 1, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.

  • CVE-2016-6080MedFeb 1, 2017
    risk 0.34cvss 5.3epss 0.00

    The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.

  • CVE-2016-5896MedFeb 1, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.

  • CVE-2016-3035MedFeb 1, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.

  • CVE-2016-3023MedFeb 1, 2017
    risk 0.34cvss 5.3epss 0.00

    IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

  • CVE-2016-9411MedJan 31, 2017
    risk 0.34cvss 5.3epss 0.00

    The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.

  • CVE-2017-3805MedJan 26, 2017
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view confidential information that is displayed without authenticating to the device. Affected Products: This vulnerability affects Cisco IOS Software and Cisco IOx Software running on IR829, IR809, IE4K, and CGR1K platforms. More Information: CSCvb20897. Known Affected Releases: 1.0(0).