VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 21 of 30
  • CVE-2021-40126MedNov 4, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashboard that appears…

  • CVE-2021-20552MedOct 7, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.

  • CVE-2021-20485MedSep 23, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667.

  • CVE-2020-4941MedSep 23, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.

  • CVE-2021-20508MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322.

  • CVE-2021-22249MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

  • CVE-2021-29784MedJul 26, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 203168.

  • CVE-2021-20424MedJul 13, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309.

  • CVE-2021-20417MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196219

  • CVE-2021-20413MedJun 28, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196212.

  • CVE-2021-32712MedJun 24, 2021
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download…

  • CVE-2021-31341MedMay 12, 2021
    risk 0.28cvss 4.3epss 0.01

    Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).

  • CVE-2021-31339MedMay 12, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework.

  • CVE-2020-4536MedMay 11, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.

  • CVE-2021-3393MedApr 1, 2021
    risk 0.28cvss 4.3epss 0.01

    An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in…

  • CVE-2021-22169MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

  • CVE-2021-23968MedFeb 26, 2021
    risk 0.28cvss 4.3epss 0.01

    If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability…

  • CVE-2020-15219MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2020-4544MedJan 8, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.

  • CVE-2020-4487MedJan 8, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181862.