CWE-209
Generation of Error Message Containing Sensitive Information
Description
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7
CVEs mapped to this weakness (629)
page 22 of 32| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39018 | Med | 0.28 | 4.3 | 0.01 | Jul 14, 2022 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726. | ||
| CVE-2022-31047 | Med | 0.28 | 5.3 | 0.01 | Jun 14, 2022 | TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete… | ||
| CVE-2022-26070 | Med | 0.28 | 4.3 | 0.01 | May 6, 2022 | When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0. | ||
| CVE-2021-43206 | Med | 0.28 | 4.3 | 0.01 | May 4, 2022 | A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin… | ||
| CVE-2022-0622 | Med | 0.28 | 5.3 | 0.01 | Feb 17, 2022 | Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11. | ||
| CVE-2022-0083 | Med | 0.28 | 5.3 | 0.01 | Jan 4, 2022 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information | ||
| CVE-2022-0079 | Med | 0.28 | 5.3 | 0.01 | Jan 3, 2022 | showdoc is vulnerable to Generation of Error Message Containing Sensitive Information | ||
| CVE-2021-40126 | Med | 0.28 | 4.3 | 0.01 | Nov 4, 2021 | A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashboard that appears… | ||
| CVE-2021-20552 | Med | 0.28 | 4.3 | 0.01 | Oct 7, 2021 | IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170. | ||
| CVE-2021-20485 | Med | 0.28 | 4.3 | 0.01 | Sep 23, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667. | ||
| CVE-2020-4941 | Med | 0.28 | 4.3 | 0.01 | Sep 23, 2021 | IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941. | ||
| CVE-2021-20508 | Med | 0.28 | 4.3 | 0.01 | Sep 14, 2021 | IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322. | ||
| CVE-2021-22249 | Med | 0.28 | 4.3 | 0.01 | Aug 23, 2021 | A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group | ||
| CVE-2021-29784 | Med | 0.28 | 4.3 | 0.01 | Jul 26, 2021 | IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 203168. | ||
| CVE-2021-20424 | Med | 0.28 | 4.3 | 0.01 | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309. | ||
| CVE-2021-20417 | Med | 0.28 | 4.3 | 0.01 | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196219 | ||
| CVE-2021-20413 | Med | 0.28 | 4.3 | 0.01 | Jun 28, 2021 | IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196212. | ||
| CVE-2021-32712 | Med | 0.28 | 5.3 | 0.01 | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download… | ||
| CVE-2021-31341 | Med | 0.28 | 4.3 | 0.01 | May 12, 2021 | Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1). | ||
| CVE-2021-31339 | Med | 0.28 | 4.3 | 0.01 | May 12, 2021 | A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework. |
- risk 0.28cvss 4.3epss 0.01
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726.
- risk 0.28cvss 5.3epss 0.01
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete…
- risk 0.28cvss 4.3epss 0.01
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.
- risk 0.28cvss 4.3epss 0.01
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin…
- risk 0.28cvss 5.3epss 0.01
Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
- risk 0.28cvss 5.3epss 0.01
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
- risk 0.28cvss 5.3epss 0.01
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
- risk 0.28cvss 4.3epss 0.01
A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashboard that appears…
- risk 0.28cvss 4.3epss 0.01
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.
- risk 0.28cvss 4.3epss 0.01
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667.
- risk 0.28cvss 4.3epss 0.01
IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.
- risk 0.28cvss 4.3epss 0.01
IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322.
- risk 0.28cvss 4.3epss 0.01
A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group
- risk 0.28cvss 4.3epss 0.01
IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 203168.
- risk 0.28cvss 4.3epss 0.01
IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309.
- risk 0.28cvss 4.3epss 0.01
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196219
- risk 0.28cvss 4.3epss 0.01
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196212.
- risk 0.28cvss 5.3epss 0.01
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download…
- risk 0.28cvss 4.3epss 0.01
Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).
- risk 0.28cvss 4.3epss 0.01
A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework.