VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 12 of 32
  • CVE-2020-4166MedAug 27, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 174402.

  • CVE-2020-8213MedJul 30, 2020
    risk 0.35cvss 5.3epss 0.01

    An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing.

  • CVE-2020-4572MedJul 29, 2020
    risk 0.35cvss 5.3epss 0.02

    IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184179.

  • CVE-2020-4341MedJun 24, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178181.

  • CVE-2020-4327MedJun 24, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 177599.

  • CVE-2020-4532MedJun 17, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This…

  • CVE-2019-18865MedMay 7, 2020
    risk 0.35cvss 5.3epss 0.01

    Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.

  • CVE-2020-4239MedMar 31, 2020
    risk 0.35cvss 5.3epss 0.02

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175412.

  • CVE-2020-10097MedMar 5, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities.

  • CVE-2019-19993MedFeb 26, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnerability were discovered. A user, even with no authentication, may simply send arbitrary content to the vulnerable pages to generate error messages that expose…

  • CVE-2020-9351MedFeb 23, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the _transaction parameter, the server replies with a verbose error showing where the…

  • CVE-2020-6189MedFeb 12, 2020
    risk 0.35cvss 5.3epss 0.01

    Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information Disclosure.

  • CVE-2020-7231MedJan 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.

  • CVE-2019-19806MedDec 30, 2019
    risk 0.35cvss 5.3epss 0.01

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

  • CVE-2019-19342MedDec 19, 2019
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial…

  • CVE-2013-6879MedNov 22, 2019
    risk 0.35cvss 5.3epss 0.01

    The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message.

  • CVE-2019-4570MedNov 22, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 166720.

  • CVE-2019-4441MedOct 3, 2019
    risk 0.35cvss 5.3epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.

  • CVE-2019-12156MedOct 2, 2019
    risk 0.35cvss 5.3epss 0.01

    Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.

  • CVE-2019-15032MedSep 19, 2019
    risk 0.35cvss 5.3epss 0.02

    Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal…