VYPR

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

ClassDraftLikelihood: High

Description

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-116 · CAPEC-13 · CAPEC-169 · CAPEC-22 · CAPEC-224 · CAPEC-285 · CAPEC-287 · CAPEC-290 · CAPEC-291 · CAPEC-292 · CAPEC-293 · CAPEC-294 · CAPEC-295 · CAPEC-296 · CAPEC-297 · CAPEC-298 · CAPEC-299 · CAPEC-300 · CAPEC-301 · CAPEC-302 · CAPEC-303 · CAPEC-304 · CAPEC-305 · CAPEC-306 · CAPEC-307 · CAPEC-308 · CAPEC-309 · CAPEC-310 · CAPEC-312 · CAPEC-313 · CAPEC-317 · CAPEC-318 · CAPEC-319 · CAPEC-320 · CAPEC-321 · CAPEC-322 · CAPEC-323 · CAPEC-324 · CAPEC-325 · CAPEC-326 · CAPEC-327 · CAPEC-328 · CAPEC-329 · CAPEC-330 · CAPEC-472 · CAPEC-497 · CAPEC-508 · CAPEC-573 · CAPEC-574 · CAPEC-575 · CAPEC-576 · CAPEC-577 · CAPEC-59 · CAPEC-60 · CAPEC-616 · CAPEC-643 · CAPEC-646 · CAPEC-651 · CAPEC-79

CVEs mapped to this weakness (6,463)

page 154 of 324
  • CVE-2015-3400MedOct 18, 2017
    risk 0.21cvss 4.3epss 0.00

    sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.

  • CVE-2017-14772LowOct 3, 2017
    risk 0.21cvss 3.3epss 0.00

    Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing error messages upon valid and invalid account login attempts.

  • CVE-2015-5069MedSep 26, 2017
    risk 0.21cvss 4.3epss 0.01

    The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl…

  • CVE-2015-0238LowSep 26, 2017
    risk 0.21cvss 3.3epss 0.00

    selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.

  • CVE-2017-12157MedSep 18, 2017
    risk 0.21cvss 4.3epss 0.00

    In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

  • CVE-2016-2978LowAug 29, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.

  • CVE-2016-2974LowAug 29, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.

  • CVE-2017-1422LowAug 22, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412.

  • CVE-2017-1381LowJul 21, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.

  • CVE-2017-7531MedJul 17, 2017
    risk 0.21cvss 4.3epss 0.00

    In Moodle 3.3, the course overview block reveals activities in hidden courses.

  • CVE-2017-0709LowJul 6, 2017
    risk 0.21cvss 3.3epss 0.00

    A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.

  • CVE-2017-1176LowJul 5, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.

  • CVE-2015-9032LowJun 13, 2017
    risk 0.21cvss 3.3epss 0.00

    In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.

  • CVE-2015-9031LowJun 13, 2017
    risk 0.21cvss 3.3epss 0.00

    In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.

  • CVE-2017-1125LowJun 7, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.

  • CVE-2017-3589LowApr 24, 2017
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors…

  • CVE-2017-3498LowApr 24, 2017
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to…

  • CVE-2014-9680LowApr 24, 2017
    risk 0.21cvss 3.3epss 0.00

    sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with…

  • CVE-2016-2565LowApr 13, 2017
    risk 0.21cvss 3.3epss 0.00

    Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081.

  • CVE-2016-8757LowApr 2, 2017
    risk 0.21cvss 3.3epss 0.00

    ION memory management module in Huawei P9 phones with software EVA-AL10C00B192 and earlier versions, EVA-DL10C00B192 and earlier versions, EVA-TL10C00B192 and earlier versions, EVA-CL10C00B192 and earlier versions allows attackers to obtain sensitive information from…