VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 18 of 30
  • CVE-2026-1248MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.

  • CVE-2026-9583MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message.…

  • CVE-2026-2484MedMar 25, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information exposure vulnerability caused by overly verbose error messages

  • CVE-2026-1262MedMar 25, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.

  • CVE-2026-21783MedMar 24, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler is affected by sensitive information disclosure.  The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.  Attackers…

  • CVE-2026-22052MedMar 5, 2026
    risk 0.28cvss 4.3epss 0.00

    ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.

  • CVE-2026-22646MedJan 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the…

  • CVE-2025-13978MedDec 11, 2025
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to discover the names of private projects they do not have access through API requests.

  • CVE-2025-36437MedDec 9, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system.

  • CVE-2025-52671MedNov 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

  • CVE-2025-54562MedNov 14, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack trace.

  • CVE-2025-8852MedAug 11, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack…

  • CVE-2025-36090MedJul 10, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be used in reconnaissance to gather information for future attacks from a detailed technical error message.

  • CVE-2024-56342MedJun 6, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2025-25025MedMay 28, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2025-25045MedApr 23, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.

  • CVE-2025-32238MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Retrieve Embedded Sensitive Data.This issue affects Online Booking & Scheduling Calendar for…

  • CVE-2025-0279MedApr 3, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's…

  • CVE-2024-49798MedFeb 6, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2024-35111MedJan 25, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.