VYPR

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

ClassDraftLikelihood: High

Description

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-116 · CAPEC-13 · CAPEC-169 · CAPEC-22 · CAPEC-224 · CAPEC-285 · CAPEC-287 · CAPEC-290 · CAPEC-291 · CAPEC-292 · CAPEC-293 · CAPEC-294 · CAPEC-295 · CAPEC-296 · CAPEC-297 · CAPEC-298 · CAPEC-299 · CAPEC-300 · CAPEC-301 · CAPEC-302 · CAPEC-303 · CAPEC-304 · CAPEC-305 · CAPEC-306 · CAPEC-307 · CAPEC-308 · CAPEC-309 · CAPEC-310 · CAPEC-312 · CAPEC-313 · CAPEC-317 · CAPEC-318 · CAPEC-319 · CAPEC-320 · CAPEC-321 · CAPEC-322 · CAPEC-323 · CAPEC-324 · CAPEC-325 · CAPEC-326 · CAPEC-327 · CAPEC-328 · CAPEC-329 · CAPEC-330 · CAPEC-472 · CAPEC-497 · CAPEC-508 · CAPEC-573 · CAPEC-574 · CAPEC-575 · CAPEC-576 · CAPEC-577 · CAPEC-59 · CAPEC-60 · CAPEC-616 · CAPEC-643 · CAPEC-646 · CAPEC-651 · CAPEC-79

CVEs mapped to this weakness (6,463)

page 134 of 324
  • CVE-2017-5000MedJul 7, 2017
    risk 0.28cvss 4.3epss 0.00

    EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an information exposure through an error message vulnerability. A remote low privileged attacker may potentially exploit this vulnerability to use information disclosed in an error message to…

  • CVE-2017-1157MedJul 5, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.

  • CVE-2016-9700MedJul 5, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528.

  • CVE-2017-2180MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.00

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors.

  • CVE-2016-8987MedJun 8, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.

  • CVE-2017-8441MedJun 5, 2017
    risk 0.28cvss 4.3epss 0.00

    Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an…

  • CVE-2017-7488MedMay 16, 2017
    risk 0.28cvss 4.3epss 0.00

    Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.

  • CVE-2016-9735MedMay 15, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,

  • CVE-2017-1141MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.

  • CVE-2017-2093MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.00

    Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.

  • CVE-2017-3560MedApr 24, 2017
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OXI Interface). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily "exploitable" vulnerability…

  • CVE-2017-3552MedApr 24, 2017
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Room Image/Picture Setup). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily "exploitable"…

  • CVE-2016-9978MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.

  • CVE-2016-8923MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.

  • CVE-2016-3732MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.00

    The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.

  • CVE-2016-4844MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.

  • CVE-2016-4842MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.00

    Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.

  • CVE-2016-4872MedApr 17, 2017
    risk 0.28cvss 4.3epss 0.00

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.

  • CVE-2016-4867MedApr 17, 2017
    risk 0.28cvss 4.3epss 0.00

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.

  • CVE-2016-8926MedApr 14, 2017
    risk 0.28cvss 4.3epss 0.00

    IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.