VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 20 of 30
  • CVE-2023-33834MedAug 31, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-force ID: 256014.

  • CVE-2023-40338MedAug 16, 2023
    risk 0.28cvss 4.3epss 0.01

    Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.

  • CVE-2020-4868MedJul 31, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190744.

  • CVE-2023-33181MedMay 30, 2023
    risk 0.28cvss 4.3epss 0.01

    Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using. Users…

  • CVE-2023-31286MedApr 27, 2023
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.

  • CVE-2022-4770MedApr 3, 2023
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). 

  • CVE-2022-4769MedApr 3, 2023
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name. 

  • CVE-2023-25687MedMar 21, 2023
    risk 0.28cvss 4.3epss 0.00

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.

  • CVE-2023-25695MedMar 15, 2023
    risk 0.28cvss 5.3epss 0.01

    Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.

  • CVE-2020-5026MedMar 1, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks…

  • CVE-2022-2760MedSep 28, 2022
    risk 0.28cvss 4.3epss 0.00

    In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.

  • CVE-2022-33930MedAug 10, 2022
    risk 0.28cvss 4.3epss 0.01

    Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to…

  • CVE-2022-31189MedAug 1, 2022
    risk 0.28cvss 5.3epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. When an "Internal System Error" occurs in the JSPUI, then entire exception (including stack trace) is available. Information in…

  • CVE-2021-39018MedJul 14, 2022
    risk 0.28cvss 4.3epss 0.01

    IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726.

  • CVE-2022-31047MedJun 14, 2022
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete…

  • CVE-2022-26070MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.01

    When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.

  • CVE-2021-43206MedMay 4, 2022
    risk 0.28cvss 4.3epss 0.01

    A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin…

  • CVE-2022-0622MedFeb 17, 2022
    risk 0.28cvss 5.3epss 0.01

    Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.

  • CVE-2022-0083MedJan 4, 2022
    risk 0.28cvss 5.3epss 0.01

    livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

  • CVE-2022-0079MedJan 3, 2022
    risk 0.28cvss 5.3epss 0.01

    showdoc is vulnerable to Generation of Error Message Containing Sensitive Information