VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (599)

page 25 of 30
  • CVE-2025-0049LowApr 28, 2025
    risk 0.23cvss 3.5epss 0.00

    When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.

  • CVE-2024-52611LowFeb 11, 2025
    risk 0.23cvss 3.5epss 0.00

    The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions.

  • CVE-2023-50355LowOct 23, 2024
    risk 0.23cvss 3.6epss 0.00

    HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.

  • CVE-2024-8571LowSep 8, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. The manipulation leads to information exposure through error message. This…

  • CVE-2024-5250LowJul 30, 2024
    risk 0.23cvss 3.5epss 0.00

    In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

  • CVE-2024-3454LowJul 24, 2024
    risk 0.23cvss 3.5epss 0.00

    An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed to prevent access to such…

  • CVE-2021-22193LowMar 24, 2021
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

  • CVE-2019-18947LowFeb 26, 2021
    risk 0.23cvss 3.5epss 0.00

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.

  • CVE-2020-5274MedMar 30, 2020
    risk 0.23cvss 4.6epss 0.01

    In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the…

  • CVE-2025-4166MedMay 2, 2025
    risk 0.22cvss 4.5epss 0.00

    Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified…

  • CVE-2024-5435MedSep 12, 2024
    risk 0.22cvss 4.5epss 0.00

    An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

  • CVE-2026-28786MedMar 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an unsanitized filename field in the speech-to-text transcription endpoint allows any authenticated non-admin user to trigger a `FileNotFoundError` whose…

  • CVE-2025-62840LowJan 2, 2026
    risk 0.21cvss 3.3epss 0.00

    A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the…

  • CVE-2025-64749MedNov 13, 2025
    risk 0.21cvss 4.3epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API returns different error messages for…

  • CVE-2025-59016MedSep 9, 2025
    risk 0.21cvss 4.3epss 0.00

    Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.

  • CVE-2024-56812LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56811LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56810LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56496LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56495LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.