VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 27 of 32
  • CVE-2025-62840LowJan 2, 2026
    risk 0.21cvss 3.3epss 0.00

    A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the…

  • CVE-2025-64749MedNov 13, 2025
    risk 0.21cvss 4.3epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API returns different error messages for…

  • CVE-2025-59016MedSep 9, 2025
    risk 0.21cvss 4.3epss 0.00

    Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.

  • CVE-2024-56812LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56811LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56810LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56496LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56495LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56494LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56493LowFeb 27, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2024-56467LowFeb 6, 2025
    risk 0.21cvss 3.3epss 0.00

    IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2021-3986MedNov 15, 2024
    risk 0.21cvss 4.3epss 0.00

    A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book…

  • CVE-2024-43376MedAug 20, 2024
    risk 0.21cvss 4.3epss 0.00

    Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.

  • CVE-2024-36106MedJun 6, 2024
    risk 0.21cvss 4.3epss 0.00

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the…

  • CVE-2024-32046MedApr 26, 2024
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are…

  • CVE-2023-34339LowJun 1, 2023
    risk 0.21cvss 3.3epss 0.00

    In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message

  • CVE-2022-20525LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-34881LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows local users to gain sensitive information. This issue affects JP1/Automatic Operation: from 10-00 through 10-54-03, from 11-00 before 11-51-09, from 12-00 before…

  • CVE-2020-16121LowNov 7, 2020
    risk 0.21cvss 3.3epss 0.00

    PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.

  • CVE-2020-4629LowSep 30, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.