VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 28 of 32
  • CVE-2025-52611LowJun 4, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object…

  • CVE-2025-59853LowMay 6, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic, and environment configurations.

  • CVE-2023-50348LowJan 3, 2024
    risk 0.20cvss 3.1epss 0.00

    HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system, etc.

  • CVE-2023-35124LowSep 5, 2023
    risk 0.20cvss 3.1epss 0.01

    An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a…

  • CVE-2023-1210LowAug 2, 2023
    risk 0.20cvss 3.1epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for groups that restrict…

  • CVE-2021-27774LowSep 22, 2022
    risk 0.20cvss 3.1epss 0.00

    User input included in error response, which could be used in a phishing attack.

  • CVE-2019-6122LowNov 6, 2019
    risk 0.20cvss 3.1epss 0.01

    A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct…

  • CVE-2025-52641LowApr 15, 2026
    risk 0.19cvss 2.9epss 0.00

    HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited…

  • CVE-2025-49128MedJun 6, 2025
    risk 0.19cvss 4.0epss 0.00

    Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocation._appendSourceDesc` method allows up to 500 bytes of…

  • CVE-2024-37162MedJun 7, 2024
    risk 0.19cvss 4.0epss 0.00

    zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers the parse error stack from the server to the client in production build mode. This can potentially reveal sensitive information about the server environment,…

  • CVE-2026-5511LowMay 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.  An authenticated attacker with administrative privileges could exploit this…

  • CVE-2025-13596LowNov 24, 2025
    risk 0.18cvss —epss 0.00

    A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack…

  • CVE-2024-55895LowMar 29, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2025-31141LowMar 27, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page

  • CVE-2024-45658LowFeb 4, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

  • CVE-2022-32756LowMar 22, 2024
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 228507.

  • CVE-2022-43891LowOct 17, 2023
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.

  • CVE-2021-38894LowJan 10, 2022
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 209515.

  • CVE-2021-20377LowSep 23, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

  • CVE-2021-20523LowJul 15, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 198660