VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 27 of 30
  • CVE-2025-52641LowApr 15, 2026
    risk 0.19cvss 2.9epss 0.00

    HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited…

  • CVE-2025-49128MedJun 6, 2025
    risk 0.19cvss 4.0epss 0.00

    Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocation._appendSourceDesc` method allows up to 500 bytes of…

  • CVE-2024-37162MedJun 7, 2024
    risk 0.19cvss 4.0epss 0.00

    zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers the parse error stack from the server to the client in production build mode. This can potentially reveal sensitive information about the server environment,…

  • CVE-2026-5511LowMay 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.  An authenticated attacker with administrative privileges could exploit this…

  • CVE-2025-13596LowNov 24, 2025
    risk 0.18cvss epss 0.00

    A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack…

  • CVE-2024-55895LowMar 29, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2025-31141LowMar 27, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page

  • CVE-2024-45658LowFeb 4, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2022-32756LowMar 22, 2024
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 228507.

  • CVE-2022-43891LowOct 17, 2023
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.

  • CVE-2021-38894LowJan 10, 2022
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 209515.

  • CVE-2021-20377LowSep 23, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

  • CVE-2021-20523LowJul 15, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 198660

  • CVE-2021-20499LowJul 15, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197973

  • CVE-2020-1717LowFeb 11, 2021
    risk 0.18cvss 2.7epss 0.01

    A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.

  • CVE-2021-20402LowFeb 11, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196076.

  • CVE-2020-4846LowDec 17, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190290.

  • CVE-2019-4699LowAug 26, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 171931.

  • CVE-2020-4248LowMay 28, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175484.

  • CVE-2020-4164LowApr 8, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could expose sensitive information from applicatino errors which could be used in further attacks against the system. IBM X-Force ID: 174400.