CWE-209
Generation of Error Message Containing Sensitive Information
Description
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7
CVEs mapped to this weakness (629)
page 17 of 32| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-26272 | Med | 0.34 | 5.3 | 0.00 | Aug 28, 2023 | IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the… | ||
| CVE-2023-32755 | Med | 0.34 | 5.3 | 0.01 | Aug 25, 2023 | e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command. | ||
| CVE-2023-3362 | Med | 0.34 | 5.3 | 0.01 | Jul 13, 2023 | An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub. | ||
| CVE-2022-4870 | Med | 0.34 | 5.3 | 0.00 | May 18, 2023 | In affected versions of Octopus Deploy it is possible to discover network details via error message | ||
| CVE-2023-27860 | Med | 0.34 | 5.3 | 0.01 | Apr 27, 2023 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207. | ||
| CVE-2022-46675 | Med | 0.34 | 5.3 | 0.00 | Feb 11, 2023 | Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research. | ||
| CVE-2022-46371 | Med | 0.34 | 5.3 | 0.00 | Jan 12, 2023 | Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name. | ||
| CVE-2022-40292 | Med | 0.34 | 5.3 | 0.01 | Oct 31, 2022 | The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system. | ||
| CVE-2022-2508 | Med | 0.34 | 5.3 | 0.01 | Oct 27, 2022 | In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging. | ||
| CVE-2022-38107 | Med | 0.34 | 5.3 | 0.01 | Oct 19, 2022 | Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details. | ||
| CVE-2026-54561 | Med | 0.33 | 6.2 | 0.00 | Sep 15, 2026 | MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client,… | ||
| CVE-2025-48562 | Med | 0.33 | 5.0 | 0.00 | Sep 4, 2025 | In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. | ||
| CVE-2024-45713 | Med | 0.33 | 5.1 | 0.00 | Oct 17, 2024 | SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes. | ||
| CVE-2025-36348 | Med | 0.32 | 4.9 | 0.00 | Feb 17, 2026 | IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a… | ||
| CVE-2025-46575 | Med | 0.32 | 4.9 | 0.00 | Apr 27, 2025 | There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information. | ||
| CVE-2020-4842 | Med | 0.32 | 4.9 | 0.01 | Dec 21, 2020 | IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190046. | ||
| CVE-2017-1370 | Med | 0.32 | 4.9 | 0.01 | Jul 31, 2017 | IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863. | ||
| CVE-2012-0059 | Med | 0.32 | 4.9 | 0.02 | Feb 5, 2014 | A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails,… | ||
| CVE-2026-92936 | — | Med | 0.31 | 5.8 | 0.00 | Sep 17, 2026 | vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed source) and then read… | |
| CVE-2026-55102 | Med | 0.31 | — | 0.00 | Sep 14, 2026 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response… |
- risk 0.34cvss 5.3epss 0.00
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the…
- risk 0.34cvss 5.3epss 0.01
e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.
- risk 0.34cvss 5.3epss 0.01
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to discover network details via error message
- risk 0.34cvss 5.3epss 0.01
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207.
- risk 0.34cvss 5.3epss 0.00
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research.
- risk 0.34cvss 5.3epss 0.00
Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.
- risk 0.34cvss 5.3epss 0.01
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.
- risk 0.34cvss 5.3epss 0.01
In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.
- risk 0.34cvss 5.3epss 0.01
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details.
- risk 0.33cvss 6.2epss 0.00
MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client,…
- risk 0.33cvss 5.0epss 0.00
In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
- risk 0.33cvss 5.1epss 0.00
SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes.
- risk 0.32cvss 4.9epss 0.00
IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a…
- risk 0.32cvss 4.9epss 0.00
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
- risk 0.32cvss 4.9epss 0.01
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190046.
- risk 0.32cvss 4.9epss 0.01
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
- risk 0.32cvss 4.9epss 0.02
A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails,…
- risk 0.31cvss 5.8epss 0.00
vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed source) and then read…
- risk 0.31cvss —epss 0.00
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response…