VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 11 of 32
  • CVE-2021-35947MedSep 7, 2021
    risk 0.35cvss 5.3epss 0.01

    The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.

  • CVE-2021-29767MedJul 26, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID:…

  • CVE-2021-29766MedJul 26, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM…

  • CVE-2021-20430MedJul 26, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM…

  • CVE-2021-25809MedJul 23, 2021
    risk 0.35cvss 5.3epss 0.01

    UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

  • CVE-2021-33711MedJul 13, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). The affected application allows verbose error messages which allow…

  • CVE-2020-20470MedJun 21, 2021
    risk 0.35cvss 5.3epss 0.01

    White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.

  • CVE-2021-20428MedMay 24, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315.

  • CVE-2021-29682MedMay 20, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199997

  • CVE-2021-29040MedMay 16, 2021
    risk 0.35cvss 5.3epss 0.01

    The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch…

  • CVE-2020-19275MedMay 12, 2021
    risk 0.35cvss 5.3epss 0.01

    An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.

  • CVE-2021-20289MedMar 26, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's…

  • CVE-2020-4628MedJan 27, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 185369.

  • CVE-2020-4600MedJan 13, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184832.

  • CVE-2020-4599MedJan 13, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184824.

  • CVE-2020-4897MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.02

    IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against…

  • CVE-2020-4761MedJan 5, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in…

  • CVE-2020-4907MedDec 16, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2020-25640MedNov 24, 2020
    risk 0.35cvss 5.3epss 0.01

    A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.

  • CVE-2019-4547MedOct 29, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949.