VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 3 of 30
  • CVE-2024-23689HigJan 19, 2024
    risk 0.50cvss 8.8epss 0.01

    Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs.…

  • CVE-2023-29193HigApr 14, 2023
    risk 0.50cvss 8.7epss 0.01

    SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the gRPC API from being accessed by…

  • CVE-2021-32775HigJul 21, 2021
    risk 0.50cvss 7.7epss 0.01

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.

  • CVE-2026-13182HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.

  • CVE-2025-71282HigApr 1, 2026
    risk 0.49cvss 7.5epss 0.00

    XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.

  • CVE-2022-50686HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to…

  • CVE-2025-36003HigAug 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.

  • CVE-2025-23320HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shared memory limit to be exceeded by sending a very large request. A successful exploit of this vulnerability might lead to information…

  • CVE-2025-40718HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to send malformed payloads to generate error messages containing sensitive information.

  • CVE-2025-44203HigJun 20, 2025
    risk 0.49cvss 7.5epss 0.01

    In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL…

  • CVE-2024-54141HigDec 6, 2024
    risk 0.49cvss 8.6epss 0.00

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie postgreSQL) server's credential when connection to DB fails. This vulnerability is fixed in 4.0.0.

  • CVE-2024-39719HigOct 31, 2024
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, providing a primitive for file…

  • CVE-2023-25948HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-37306HigJun 30, 2023
    risk 0.49cvss 7.5epss 0.01

    MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

  • CVE-2023-23837HigApr 25, 2023
    risk 0.49cvss 7.5epss 0.01

    No exception handling vulnerability which revealed sensitive or excessive information to users.

  • CVE-2023-22626HigJan 5, 2023
    risk 0.49cvss 7.5epss 0.01

    PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)

  • CVE-2021-38924HigSep 14, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.

  • CVE-2022-35715HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.

  • CVE-2021-39023HigMay 6, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213860.

  • CVE-2022-29266HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.08

    In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.