CWE-209
Generation of Error Message Containing Sensitive Information
Description
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7
CVEs mapped to this weakness (600)
page 26 of 30| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56494 | Low | 0.21 | 3.3 | 0.00 | Feb 27, 2025 | IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. | ||
| CVE-2024-56493 | Low | 0.21 | 3.3 | 0.00 | Feb 27, 2025 | IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. | ||
| CVE-2024-56467 | Low | 0.21 | 3.3 | 0.00 | Feb 6, 2025 | IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. | ||
| CVE-2021-3986 | Med | 0.21 | 4.3 | 0.00 | Nov 15, 2024 | A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book… | ||
| CVE-2024-43376 | Med | 0.21 | 4.3 | 0.00 | Aug 20, 2024 | Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2. | ||
| CVE-2024-36106 | Med | 0.21 | 4.3 | 0.00 | Jun 6, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the… | ||
| CVE-2024-32046 | Med | 0.21 | 4.3 | 0.00 | Apr 26, 2024 | Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are… | ||
| CVE-2023-34339 | Low | 0.21 | 3.3 | 0.00 | Jun 1, 2023 | In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message | ||
| CVE-2022-20525 | Low | 0.21 | 3.3 | 0.00 | Dec 16, 2022 | In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed… | ||
| CVE-2022-34881 | Low | 0.21 | 3.3 | 0.00 | Dec 6, 2022 | Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows local users to gain sensitive information. This issue affects JP1/Automatic Operation: from 10-00 through 10-54-03, from 11-00 before 11-51-09, from 12-00 before… | ||
| CVE-2020-16121 | Low | 0.21 | 3.3 | 0.00 | Nov 7, 2020 | PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own. | ||
| CVE-2020-4629 | Low | 0.21 | 3.3 | 0.00 | Sep 30, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370. | ||
| CVE-2025-52611 | Low | 0.20 | 3.1 | 0.00 | Jun 4, 2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object… | ||
| CVE-2025-59853 | Low | 0.20 | 3.1 | 0.00 | May 6, 2026 | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations. | ||
| CVE-2023-50348 | Low | 0.20 | 3.1 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system, etc. | ||
| CVE-2023-35124 | Low | 0.20 | 3.1 | 0.01 | Sep 5, 2023 | An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a… | ||
| CVE-2023-1210 | Low | 0.20 | 3.1 | 0.01 | Aug 2, 2023 | An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict… | ||
| CVE-2021-27774 | Low | 0.20 | 3.1 | 0.00 | Sep 22, 2022 | User input included in error response, which could be used in a phishing attack. | ||
| CVE-2019-6122 | Low | 0.20 | 3.1 | 0.01 | Nov 6, 2019 | A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct… | ||
| CVE-2026-54561 | med | 0.19 | — | — | Jul 17, 2026 | ### Impact `context_import` passed the caller-supplied `filePath` directly to `fs.readFileSync` with no path confinement. A malicious MCP client — or an LLM agent that is prompt-injected into calling the tool — could point `filePath` at **any file readable by the server… |
- risk 0.21cvss 3.3epss 0.00
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
- risk 0.21cvss 3.3epss 0.00
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
- risk 0.21cvss 3.3epss 0.00
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
- risk 0.21cvss 4.3epss 0.00
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book…
- risk 0.21cvss 4.3epss 0.00
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.
- risk 0.21cvss 4.3epss 0.00
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the…
- risk 0.21cvss 4.3epss 0.00
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are…
- risk 0.21cvss 3.3epss 0.00
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
- risk 0.21cvss 3.3epss 0.00
In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- risk 0.21cvss 3.3epss 0.00
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows local users to gain sensitive information. This issue affects JP1/Automatic Operation: from 10-00 through 10-54-03, from 11-00 before 11-51-09, from 12-00 before…
- risk 0.21cvss 3.3epss 0.00
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
- risk 0.21cvss 3.3epss 0.00
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
- risk 0.20cvss 3.1epss 0.00
HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object…
- risk 0.20cvss 3.1epss 0.00
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations.
- risk 0.20cvss 3.1epss 0.00
HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system, etc.
- risk 0.20cvss 3.1epss 0.01
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a…
- risk 0.20cvss 3.1epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict…
- risk 0.20cvss 3.1epss 0.00
User input included in error response, which could be used in a phishing attack.
- risk 0.20cvss 3.1epss 0.01
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct…
- risk 0.19cvss —epss —
### Impact `context_import` passed the caller-supplied `filePath` directly to `fs.readFileSync` with no path confinement. A malicious MCP client — or an LLM agent that is prompt-injected into calling the tool — could point `filePath` at **any file readable by the server…