CWE-209
Generation of Error Message Containing Sensitive Information
Description
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7
CVEs mapped to this weakness (600)
page 12 of 30| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-6189 | Med | 0.35 | 5.3 | 0.01 | Feb 12, 2020 | Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information Disclosure. | ||
| CVE-2020-7231 | Med | 0.35 | 5.3 | 0.01 | Jan 19, 2020 | Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid. | ||
| CVE-2019-19806 | Med | 0.35 | 5.3 | 0.01 | Dec 30, 2019 | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses. | ||
| CVE-2019-19342 | Med | 0.35 | 5.3 | 0.01 | Dec 19, 2019 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial… | ||
| CVE-2013-6879 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2019 | The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message. | ||
| CVE-2019-4570 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2019 | IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 166720. | ||
| CVE-2019-4441 | Med | 0.35 | 5.3 | 0.02 | Oct 3, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177. | ||
| CVE-2019-12156 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293. | ||
| CVE-2019-15032 | Med | 0.35 | 5.3 | 0.02 | Sep 19, 2019 | Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal… | ||
| CVE-2019-5483 | Med | 0.35 | 5.3 | 0.01 | Sep 9, 2019 | Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users. | ||
| CVE-2019-16101 | Med | 0.35 | 5.3 | 0.01 | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI. | ||
| CVE-2019-11602 | Med | 0.35 | 5.3 | 0.01 | Aug 21, 2019 | Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure. | ||
| CVE-2019-14433 | Med | 0.35 | 6.5 | 0.02 | Aug 9, 2019 | An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and… | ||
| CVE-2019-4129 | Med | 0.35 | 5.3 | 0.02 | Jul 2, 2019 | IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain… | ||
| CVE-2019-4219 | Med | 0.35 | 5.3 | 0.01 | Jun 6, 2019 | IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 159228. | ||
| CVE-2017-2659 | Med | 0.35 | 5.3 | 0.02 | Mar 21, 2019 | It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts. | ||
| CVE-2019-7550 | Med | 0.35 | 5.3 | 0.02 | Feb 12, 2019 | In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product… | ||
| CVE-2018-14907 | — | Med | 0.35 | 5.3 | 0.01 | Aug 3, 2018 | The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname. | |
| CVE-2018-12536 | Med | 0.35 | 5.3 | 0.04 | Jun 27, 2018 | In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a… | ||
| CVE-2018-1073 | Med | 0.35 | 5.3 | 0.02 | Jun 19, 2018 | The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts. |
- risk 0.35cvss 5.3epss 0.01
Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information Disclosure.
- risk 0.35cvss 5.3epss 0.01
Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.
- risk 0.35cvss 5.3epss 0.01
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.
- risk 0.35cvss 5.3epss 0.01
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial…
- risk 0.35cvss 5.3epss 0.01
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message.
- risk 0.35cvss 5.3epss 0.01
IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 166720.
- risk 0.35cvss 5.3epss 0.02
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
- risk 0.35cvss 5.3epss 0.01
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
- risk 0.35cvss 5.3epss 0.02
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal…
- risk 0.35cvss 5.3epss 0.01
Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.
- risk 0.35cvss 5.3epss 0.01
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.
- risk 0.35cvss 5.3epss 0.01
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.
- risk 0.35cvss 6.5epss 0.02
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and…
- risk 0.35cvss 5.3epss 0.02
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain…
- risk 0.35cvss 5.3epss 0.01
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 159228.
- risk 0.35cvss 5.3epss 0.02
It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.
- risk 0.35cvss 5.3epss 0.02
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product…
- risk 0.35cvss 5.3epss 0.01
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname.
- risk 0.35cvss 5.3epss 0.04
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a…
- risk 0.35cvss 5.3epss 0.02
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.