VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 15 of 30
  • CVE-2023-38714MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system.

  • CVE-2023-38713MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system.

  • CVE-2025-24552MedJan 24, 2025
    risk 0.34cvss 5.3epss 0.01

    Generation of Error Message Containing Sensitive Information vulnerability in paytiumsupport Paytium paytium allows Retrieve Embedded Sensitive Data.This issue affects Paytium: from n/a through <= 4.4.11.

  • CVE-2024-13536MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the /inc/class/fnm/export.php file being publicly accessible with error logging enabled. This makes it possible for unauthenticated…

  • CVE-2025-0053MedJan 14, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the…

  • CVE-2024-52893MedJan 7, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3  could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2024-39725MedDec 25, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2024-54366MedDec 16, 2024
    risk 0.34cvss 5.3epss 0.01

    Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allows Retrieve Embedded Sensitive Data.This issue affects Vimeography: from n/a through <= 2.4.4.

  • CVE-2024-52043MedNov 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.

  • CVE-2024-50512MedOct 30, 2024
    risk 0.34cvss 5.3epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows Retrieve Embedded Sensitive Data.This issue affects Posti Shipping: from n/a through <= 3.10.2.

  • CVE-2024-7426MedSep 25, 2024
    risk 0.34cvss 5.3epss 0.00

    The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php…

  • CVE-2024-6544MedSep 13, 2024
    risk 0.34cvss 5.3epss 0.00

    The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to…

  • CVE-2024-6551MedAug 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible…

  • CVE-2024-35119MedJun 30, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 290342.

  • CVE-2024-36375MedMay 29, 2024
    risk 0.34cvss 5.3epss 0.00

    In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed

  • CVE-2024-31844MedMay 21, 2024
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server. An unauthenticated user is able craft specific requests in order to make the application generate…

  • CVE-2024-30614MedApr 12, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.

  • CVE-2024-2009MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue is the function ajax_login_submit_form of the file login\index.php of the component Argument Handler. The manipulation of the argument rsargs[] leads to information exposure through…

  • CVE-2023-5617MedFeb 28, 2024
    risk 0.34cvss 5.3epss 0.00

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.

  • CVE-2024-21866MedFeb 2, 2024
    risk 0.34cvss 5.3epss 0.00

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it receives a specific malformed request.