VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (629)

page 17 of 32
  • CVE-2023-26272MedAug 28, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the…

  • CVE-2023-32755MedAug 25, 2023
    risk 0.34cvss 5.3epss 0.01

    e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.

  • CVE-2023-3362MedJul 13, 2023
    risk 0.34cvss 5.3epss 0.01

    An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.

  • CVE-2022-4870MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy it is possible to discover network details via error message

  • CVE-2023-27860MedApr 27, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207.

  • CVE-2022-46675MedFeb 11, 2023
    risk 0.34cvss 5.3epss 0.00

    Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research.

  • CVE-2022-46371MedJan 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.

  • CVE-2022-40292MedOct 31, 2022
    risk 0.34cvss 5.3epss 0.01

    The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.

  • CVE-2022-2508MedOct 27, 2022
    risk 0.34cvss 5.3epss 0.01

    In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.

  • CVE-2022-38107MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details.

  • CVE-2026-54561MedSep 15, 2026
    risk 0.33cvss 6.2epss 0.00

    MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client,…

  • CVE-2025-48562MedSep 4, 2025
    risk 0.33cvss 5.0epss 0.00

    In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-45713MedOct 17, 2024
    risk 0.33cvss 5.1epss 0.00

    SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes.

  • CVE-2025-36348MedFeb 17, 2026
    risk 0.32cvss 4.9epss 0.00

    IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a…

  • CVE-2025-46575MedApr 27, 2025
    risk 0.32cvss 4.9epss 0.00

    There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

  • CVE-2020-4842MedDec 21, 2020
    risk 0.32cvss 4.9epss 0.01

    IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190046.

  • CVE-2017-1370MedJul 31, 2017
    risk 0.32cvss 4.9epss 0.01

    IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.

  • CVE-2012-0059MedFeb 5, 2014
    risk 0.32cvss 4.9epss 0.02

    A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails,…

  • CVE-2026-92936MedSep 17, 2026
    risk 0.31cvss 5.8epss 0.00

    vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed source) and then read…

  • CVE-2026-55102MedSep 14, 2026
    risk 0.31cvss —epss 0.00

    hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response…