VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 4 of 30
  • CVE-2021-32937HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and…

  • CVE-2017-16629HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives out for each type of user on the Login form. For "Incorrect User" - it gives an error "The application failed to identify the user. Please contact…

  • CVE-2021-22885HigMay 27, 2021
    risk 0.49cvss 7.5epss 0.04

    A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.

  • CVE-2021-29688HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.

  • CVE-2021-20393HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196001.

  • CVE-2020-4584HigOct 30, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184574.

  • CVE-2020-24925HigSep 15, 2020
    risk 0.49cvss 7.5epss 0.01

    A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the path of the source code jobs/sort where entire source code path is displayed in the browser itself helping the attacker identify the code structure…

  • CVE-2020-13997HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.01

    In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.

  • CVE-2020-4277HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an attacker formulate future attacks. IBM X-Force ID: 175993.

  • CVE-2020-11594HigApr 6, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file path.

  • CVE-2019-12446HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure through an Error Message.

  • CVE-2019-0404HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.

  • CVE-2019-3730HigSep 30, 2019
    risk 0.49cvss 7.5epss 0.01

    RSA BSAFE Micro Edition Suite versions prior to 4.1.6.3 (in 4.1.x) and prior to 4.4 (in 4.2.x and 4.3.x), are vulnerable to an Information Exposure Through an Error Message vulnerability, also known as a “padding oracle attack vulnerability”. A malicious remote user could…

  • CVE-2019-7941HigJul 18, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

  • CVE-2019-4269HigJun 28, 2019
    risk 0.49cvss 7.5epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker to obtain sensitive information when a specially crafted url causes a stack trace to be dumped. IBM X-Force ID: 160202.

  • CVE-2019-9223HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.

  • CVE-2024-45817HigSep 25, 2024
    risk 0.47cvss 7.3epss 0.01

    In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can opt to receive an interrupt when a new error occurs. It is possible to configure the error interrupt with an illegal vector,…

  • CVE-2022-22162HigJan 19, 2022
    risk 0.47cvss 7.3epss 0.00

    A Generation of Error Message Containing Sensitive Information vulnerability in the CLI of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to elevate these to the level of any other user logged in via J-Web at this time, potential leading to…

  • CVE-2026-69247HigAug 3, 2026
    risk 0.46cvss epss 0.00

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several…

  • CVE-2026-3259HigApr 23, 2026
    risk 0.46cvss epss 0.00

    A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism in Google BigQuery on Google Cloud Platform allows an authenticated user to potentially disclose sensitive data using a crafted materialized view that triggers…