VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 10 of 30
  • CVE-2022-26973MedJun 2, 2022
    risk 0.35cvss 5.3epss 0.01

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.

  • CVE-2022-23794MedMar 30, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.

  • CVE-2021-35251MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.

  • CVE-2021-46353MedMar 4, 2022
    risk 0.35cvss 5.3epss 0.02

    An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.

  • CVE-2022-0504MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.01

    Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2021-44155MedDec 13, 2021
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users.

  • CVE-2021-38980MedNov 23, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further…

  • CVE-2021-38981MedNov 15, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID:…

  • CVE-2021-35060MedOct 11, 2021
    risk 0.35cvss 5.3epss 0.01

    /way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stored in the system.

  • CVE-2021-35947MedSep 7, 2021
    risk 0.35cvss 5.3epss 0.01

    The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.

  • CVE-2021-29767MedJul 26, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID:…

  • CVE-2021-29766MedJul 26, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM…

  • CVE-2021-20430MedJul 26, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM…

  • CVE-2021-25809MedJul 23, 2021
    risk 0.35cvss 5.3epss 0.01

    UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

  • CVE-2021-33711MedJul 13, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). The affected application allows verbose error messages which allow…

  • CVE-2020-20470MedJun 21, 2021
    risk 0.35cvss 5.3epss 0.01

    White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.

  • CVE-2021-20428MedMay 24, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315.

  • CVE-2021-29682MedMay 20, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199997

  • CVE-2021-29040MedMay 16, 2021
    risk 0.35cvss 5.3epss 0.01

    The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch…

  • CVE-2020-19275MedMay 12, 2021
    risk 0.35cvss 5.3epss 0.01

    An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.