VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 13 of 32
  • CVE-2019-5483MedSep 9, 2019
    risk 0.35cvss 5.3epss 0.01

    Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.

  • CVE-2019-16101MedSep 8, 2019
    risk 0.35cvss 5.3epss 0.01

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.

  • CVE-2019-11602MedAug 21, 2019
    risk 0.35cvss 5.3epss 0.01

    Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.

  • CVE-2019-14433MedAug 9, 2019
    risk 0.35cvss 6.5epss 0.02

    An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and…

  • CVE-2019-4129MedJul 2, 2019
    risk 0.35cvss 5.3epss 0.02

    IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain…

  • CVE-2019-4219MedJun 6, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 159228.

  • CVE-2017-2659MedMar 21, 2019
    risk 0.35cvss 5.3epss 0.02

    It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

  • CVE-2019-7550MedFeb 12, 2019
    risk 0.35cvss 5.3epss 0.02

    In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product…

  • CVE-2018-14907MedAug 3, 2018
    risk 0.35cvss 5.3epss 0.01

    The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname.

  • CVE-2018-12536MedJun 27, 2018
    risk 0.35cvss 5.3epss 0.04

    In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a…

  • CVE-2018-1073MedJun 19, 2018
    risk 0.35cvss 5.3epss 0.02

    The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.

  • CVE-2017-2594MedMay 8, 2018
    risk 0.35cvss 5.4epss 0.02

    hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.

  • CVE-2025-1350MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2026-82733MedSep 1, 2026
    risk 0.34cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route handler returns anything other than a…

  • CVE-2026-77950MedSep 1, 2026
    risk 0.34cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler does not match. apply_error_handler/3…

  • CVE-2026-59271MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

  • CVE-2026-8173MedAug 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network…

  • CVE-2026-47622MedAug 4, 2026
    risk 0.34cvss 5.3epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-11904MedJul 30, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive…

  • CVE-2026-8861MedJul 17, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information could be used in further attacks against the system.