VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (629)

page 22 of 32
  • CVE-2021-39018MedJul 14, 2022
    risk 0.28cvss 4.3epss 0.01

    IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726.

  • CVE-2022-31047MedJun 14, 2022
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete…

  • CVE-2022-26070MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.01

    When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.

  • CVE-2021-43206MedMay 4, 2022
    risk 0.28cvss 4.3epss 0.01

    A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.0.x allows malicious webservers to retrieve a web proxy's client username and IP via same origin…

  • CVE-2022-0622MedFeb 17, 2022
    risk 0.28cvss 5.3epss 0.01

    Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.

  • CVE-2022-0083MedJan 4, 2022
    risk 0.28cvss 5.3epss 0.01

    livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

  • CVE-2022-0079MedJan 3, 2022
    risk 0.28cvss 5.3epss 0.01

    showdoc is vulnerable to Generation of Error Message Containing Sensitive Information

  • CVE-2021-40126MedNov 4, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashboard that appears…

  • CVE-2021-20552MedOct 7, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.

  • CVE-2021-20485MedSep 23, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667.

  • CVE-2020-4941MedSep 23, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.

  • CVE-2021-20508MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322.

  • CVE-2021-22249MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group

  • CVE-2021-29784MedJul 26, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 203168.

  • CVE-2021-20424MedJul 13, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309.

  • CVE-2021-20417MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196219

  • CVE-2021-20413MedJun 28, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196212.

  • CVE-2021-32712MedJun 24, 2021
    risk 0.28cvss 5.3epss 0.01

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download…

  • CVE-2021-31341MedMay 12, 2021
    risk 0.28cvss 4.3epss 0.01

    Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).

  • CVE-2021-31339MedMay 12, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework.