VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 12 of 30
  • CVE-2020-6189MedFeb 12, 2020
    risk 0.35cvss 5.3epss 0.01

    Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information Disclosure.

  • CVE-2020-7231MedJan 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.

  • CVE-2019-19806MedDec 30, 2019
    risk 0.35cvss 5.3epss 0.01

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

  • CVE-2019-19342MedDec 19, 2019
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial…

  • CVE-2013-6879MedNov 22, 2019
    risk 0.35cvss 5.3epss 0.01

    The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message.

  • CVE-2019-4570MedNov 22, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 166720.

  • CVE-2019-4441MedOct 3, 2019
    risk 0.35cvss 5.3epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.

  • CVE-2019-12156MedOct 2, 2019
    risk 0.35cvss 5.3epss 0.01

    Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.

  • CVE-2019-15032MedSep 19, 2019
    risk 0.35cvss 5.3epss 0.02

    Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal…

  • CVE-2019-5483MedSep 9, 2019
    risk 0.35cvss 5.3epss 0.01

    Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.

  • CVE-2019-16101MedSep 8, 2019
    risk 0.35cvss 5.3epss 0.01

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.

  • CVE-2019-11602MedAug 21, 2019
    risk 0.35cvss 5.3epss 0.01

    Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.

  • CVE-2019-14433MedAug 9, 2019
    risk 0.35cvss 6.5epss 0.02

    An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and…

  • CVE-2019-4129MedJul 2, 2019
    risk 0.35cvss 5.3epss 0.02

    IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain…

  • CVE-2019-4219MedJun 6, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 159228.

  • CVE-2017-2659MedMar 21, 2019
    risk 0.35cvss 5.3epss 0.02

    It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

  • CVE-2019-7550MedFeb 12, 2019
    risk 0.35cvss 5.3epss 0.02

    In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product…

  • CVE-2018-14907MedAug 3, 2018
    risk 0.35cvss 5.3epss 0.01

    The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname.

  • CVE-2018-12536MedJun 27, 2018
    risk 0.35cvss 5.3epss 0.04

    In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a…

  • CVE-2018-1073MedJun 19, 2018
    risk 0.35cvss 5.3epss 0.02

    The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.