VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 26 of 32
  • CVE-2023-23474LowMay 3, 2024
    risk 0.24cvss 3.7epss 0.00

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.

  • CVE-2021-40338LowJan 28, 2022
    risk 0.24cvss 3.7epss 0.01

    Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi Energy LinkOne 3.20;…

  • CVE-2018-17891LowOct 4, 2018
    risk 0.24cvss 3.7epss 0.01

    Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical information an attacker could…

  • CVE-2026-56537LowJul 27, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

  • CVE-2026-4994LowMar 28, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The manipulation of the argument key results in information exposure through error…

  • CVE-2025-31998LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.

  • CVE-2024-41983LowAug 12, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application displays SQL statement in the error messages…

  • CVE-2025-0049LowApr 28, 2025
    risk 0.23cvss 3.5epss 0.00

    When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.

  • CVE-2024-52611LowFeb 11, 2025
    risk 0.23cvss 3.5epss 0.00

    The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions.

  • CVE-2023-50355LowOct 23, 2024
    risk 0.23cvss 3.6epss 0.00

    HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.

  • CVE-2024-8571LowSep 8, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. The manipulation leads to information exposure through error message. This…

  • CVE-2024-5250LowJul 30, 2024
    risk 0.23cvss 3.5epss 0.00

    In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

  • CVE-2024-3454LowJul 24, 2024
    risk 0.23cvss 3.5epss 0.00

    An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed to prevent access to such…

  • CVE-2021-22193LowMar 24, 2021
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

  • CVE-2019-18947LowFeb 26, 2021
    risk 0.23cvss 3.5epss 0.00

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.

  • CVE-2020-5274MedMar 30, 2020
    risk 0.23cvss 4.6epss 0.01

    In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the…

  • CVE-2025-4166MedMay 2, 2025
    risk 0.22cvss 4.5epss 0.00

    Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified…

  • CVE-2024-5435MedSep 12, 2024
    risk 0.22cvss 4.5epss 0.00

    An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

  • CVE-2026-63748MedJul 20, 2026
    risk 0.21cvss 4.3epss 0.00

    SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden…

  • CVE-2026-28786MedMar 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an unsanitized filename field in the speech-to-text transcription endpoint allows any authenticated non-admin user to trigger a `FileNotFoundError` whose…