CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Description
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-116 · CAPEC-13 · CAPEC-169 · CAPEC-22 · CAPEC-224 · CAPEC-285 · CAPEC-287 · CAPEC-290 · CAPEC-291 · CAPEC-292 · CAPEC-293 · CAPEC-294 · CAPEC-295 · CAPEC-296 · CAPEC-297 · CAPEC-298 · CAPEC-299 · CAPEC-300 · CAPEC-301 · CAPEC-302 · CAPEC-303 · CAPEC-304 · CAPEC-305 · CAPEC-306 · CAPEC-307 · CAPEC-308 · CAPEC-309 · CAPEC-310 · CAPEC-312 · CAPEC-313 · CAPEC-317 · CAPEC-318 · CAPEC-319 · CAPEC-320 · CAPEC-321 · CAPEC-322 · CAPEC-323 · CAPEC-324 · CAPEC-325 · CAPEC-326 · CAPEC-327 · CAPEC-328 · CAPEC-329 · CAPEC-330 · CAPEC-472 · CAPEC-497 · CAPEC-508 · CAPEC-573 · CAPEC-574 · CAPEC-575 · CAPEC-576 · CAPEC-577 · CAPEC-59 · CAPEC-60 · CAPEC-616 · CAPEC-643 · CAPEC-646 · CAPEC-651 · CAPEC-79
CVEs mapped to this weakness (6,463)
page 154 of 324| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-3400 | Med | 0.21 | 4.3 | 0.00 | Oct 18, 2017 | sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files. | ||
| CVE-2017-14772 | Low | 0.21 | 3.3 | 0.00 | Oct 3, 2017 | Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing error messages upon valid and invalid account login attempts. | ||
| CVE-2015-5069 | Med | 0.21 | 4.3 | 0.01 | Sep 26, 2017 | The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl… | ||
| CVE-2015-0238 | Low | 0.21 | 3.3 | 0.00 | Sep 26, 2017 | selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack. | ||
| CVE-2017-12157 | Med | 0.21 | 4.3 | 0.00 | Sep 18, 2017 | In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access. | ||
| CVE-2016-2978 | Low | 0.21 | 3.3 | 0.00 | Aug 29, 2017 | IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938. | ||
| CVE-2016-2974 | Low | 0.21 | 3.3 | 0.00 | Aug 29, 2017 | IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934. | ||
| CVE-2017-1422 | Low | 0.21 | 3.3 | 0.00 | Aug 22, 2017 | IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412. | ||
| CVE-2017-1381 | Low | 0.21 | 3.3 | 0.00 | Jul 21, 2017 | IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152. | ||
| CVE-2017-7531 | Med | 0.21 | 4.3 | 0.00 | Jul 17, 2017 | In Moodle 3.3, the course overview block reveals activities in hidden courses. | ||
| CVE-2017-0709 | Low | 0.21 | 3.3 | 0.00 | Jul 6, 2017 | A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048. | ||
| CVE-2017-1176 | Low | 0.21 | 3.3 | 0.00 | Jul 5, 2017 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. | ||
| CVE-2015-9032 | Low | 0.21 | 3.3 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications. | ||
| CVE-2015-9031 | Low | 0.21 | 3.3 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP. | ||
| CVE-2017-1125 | Low | 0.21 | 3.3 | 0.00 | Jun 7, 2017 | IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340. | ||
| CVE-2017-3589 | Low | 0.21 | 3.3 | 0.00 | Apr 24, 2017 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors… | ||
| CVE-2017-3498 | Low | 0.21 | 3.3 | 0.00 | Apr 24, 2017 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to… | ||
| CVE-2014-9680 | Low | 0.21 | 3.3 | 0.00 | Apr 24, 2017 | sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with… | ||
| CVE-2016-2565 | Low | 0.21 | 3.3 | 0.00 | Apr 13, 2017 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081. | ||
| CVE-2016-8757 | Low | 0.21 | 3.3 | 0.00 | Apr 2, 2017 | ION memory management module in Huawei P9 phones with software EVA-AL10C00B192 and earlier versions, EVA-DL10C00B192 and earlier versions, EVA-TL10C00B192 and earlier versions, EVA-CL10C00B192 and earlier versions allows attackers to obtain sensitive information from… |
- risk 0.21cvss 4.3epss 0.00
sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.
- risk 0.21cvss 3.3epss 0.00
Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing error messages upon valid and invalid account login attempts.
- risk 0.21cvss 4.3epss 0.01
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl…
- risk 0.21cvss 3.3epss 0.00
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.
- risk 0.21cvss 4.3epss 0.00
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
- risk 0.21cvss 3.3epss 0.00
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
- risk 0.21cvss 3.3epss 0.00
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.
- risk 0.21cvss 3.3epss 0.00
IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412.
- risk 0.21cvss 3.3epss 0.00
IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.
- risk 0.21cvss 4.3epss 0.00
In Moodle 3.3, the course overview block reveals activities in hidden courses.
- risk 0.21cvss 3.3epss 0.00
A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.
- risk 0.21cvss 3.3epss 0.00
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.
- risk 0.21cvss 3.3epss 0.00
In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.
- risk 0.21cvss 3.3epss 0.00
In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.
- risk 0.21cvss 3.3epss 0.00
IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.
- risk 0.21cvss 3.3epss 0.00
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors…
- risk 0.21cvss 3.3epss 0.00
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to…
- risk 0.21cvss 3.3epss 0.00
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with…
- risk 0.21cvss 3.3epss 0.00
Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081.
- risk 0.21cvss 3.3epss 0.00
ION memory management module in Huawei P9 phones with software EVA-AL10C00B192 and earlier versions, EVA-DL10C00B192 and earlier versions, EVA-TL10C00B192 and earlier versions, EVA-CL10C00B192 and earlier versions allows attackers to obtain sensitive information from…