VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 16 of 30
  • CVE-2024-22646MedJan 30, 2024
    risk 0.34cvss 5.3epss 0.01

    An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.

  • CVE-2023-49107MedJan 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.

  • CVE-2023-27319MedDec 21, 2023
    risk 0.34cvss 5.3epss 0.00

    ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to enumerate URLs via REST API.

  • CVE-2023-6839MedDec 15, 2023
    risk 0.34cvss 5.3epss 0.01

    Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.

  • CVE-2023-5514MedNov 1, 2023
    risk 0.34cvss 5.3epss 0.00

    The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

  • CVE-2023-37489MedSep 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's…

  • CVE-2023-26272MedAug 28, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the…

  • CVE-2023-32755MedAug 25, 2023
    risk 0.34cvss 5.3epss 0.00

    e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.

  • CVE-2023-3362MedJul 13, 2023
    risk 0.34cvss 5.3epss 0.01

    An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

  • CVE-2022-4870MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy it is possible to discover network details via error message

  • CVE-2023-27860MedApr 27, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207.

  • CVE-2022-46675MedFeb 11, 2023
    risk 0.34cvss 5.3epss 0.00

    Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research.

  • CVE-2022-46371MedJan 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.

  • CVE-2022-40292MedOct 31, 2022
    risk 0.34cvss 5.3epss 0.01

    The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.

  • CVE-2022-2508MedOct 27, 2022
    risk 0.34cvss 5.3epss 0.01

    In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.

  • CVE-2022-38107MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details.

  • CVE-2025-48562MedSep 4, 2025
    risk 0.33cvss 5.0epss 0.00

    In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-45713MedOct 17, 2024
    risk 0.33cvss 5.1epss 0.00

    SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes.

  • CVE-2025-36348MedFeb 17, 2026
    risk 0.32cvss 4.9epss 0.00

    IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a…

  • CVE-2025-46575MedApr 27, 2025
    risk 0.32cvss 4.9epss 0.00

    There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.