VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 14 of 30
  • CVE-2025-9122MedDec 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.

  • CVE-2025-61959MedOct 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors…

  • CVE-2025-12365MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-62397MedOct 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

  • CVE-2025-54291MedOct 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.

  • CVE-2025-9229MedAug 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.

  • CVE-2025-52619MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform.

  • CVE-2024-37524MedJul 10, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.

  • CVE-2025-41441MedMay 26, 2025
    risk 0.34cvss 5.3epss 0.00

    Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.

  • CVE-2025-20150MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication…

  • CVE-2025-2239MedMar 12, 2025
    risk 0.34cvss 5.3epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.

  • CVE-2025-20002MedMar 5, 2025
    risk 0.34cvss 5.3epss 0.00

    After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure

  • CVE-2024-13537MedFeb 21, 2025
    risk 0.34cvss 5.3epss 0.00

    The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible composer-setup.php file with error display enabled. This makes it possible for unauthenticated attackers…

  • CVE-2024-13540MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.00

    The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This is due the /inc/bycwooodt_get_all_orders.php file being publicly accessible and generating a…

  • CVE-2024-13538MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.01

    The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly accessible and triggering an error. This…

  • CVE-2024-13535MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.01

    The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the composer-setup.php file being publicly accessible with 'display_errors' set to true. This makes it possible for unauthenticated…

  • CVE-2024-13539MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php file being publicly accessible and displaying error messages. This makes it possible for…

  • CVE-2024-45659MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-35134MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2023-38716MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in further attacks against the system.