CWE-209
Generation of Error Message Containing Sensitive Information
Description
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7
CVEs mapped to this weakness (628)
page 8 of 32| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-47248 | Med | 0.38 | — | 0.00 | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers through Did you mean ...? suggestions embedded… | ||
| CVE-2026-44002 | Med | 0.38 | 5.8 | 0.00 | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute… | ||
| CVE-2025-26333 | Med | 0.38 | 5.9 | 0.00 | Sep 25, 2025 | Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, leading to information exposure. | ||
| CVE-2025-46746 | — | Med | 0.38 | 5.8 | 0.00 | May 12, 2025 | An administrator could discover another account's credentials. | |
| CVE-2025-0941 | Med | 0.38 | 5.8 | 0.00 | Feb 26, 2025 | MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available to unauthenticated users. | ||
| CVE-2024-44762 | Med | 0.38 | 5.3 | 0.03 | Oct 16, 2024 | A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts. | ||
| CVE-2023-47152 | Med | 0.38 | 5.9 | 0.01 | Jan 22, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions. | ||
| CVE-2021-23135 | Med | 0.38 | 5.9 | 0.00 | May 12, 2021 | Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14. | ||
| CVE-2020-14337 | Med | 0.38 | 5.8 | 0.01 | Jul 31, 2020 | A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this… | ||
| CVE-2026-69552 | Med | 0.37 | 5.7 | 0.01 | Sep 8, 2026 | Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-23216 | Med | 0.37 | 6.8 | 0.00 | Jan 30, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes… | ||
| CVE-2026-69684 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally. | ||
| CVE-2026-69294 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | ||
| CVE-2026-68886 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20838 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-40760 | Med | 0.36 | 5.5 | 0.00 | Nov 11, 2025 | A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly handle error messages and discloses sensitive password hash information when processing user authentication requests. This could allow a local attacker to… | ||
| CVE-2025-55676 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-53803 | Med | 0.36 | 5.5 | 0.01 | Sep 9, 2025 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-22421 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2025 | In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User… | ||
| CVE-2025-5731 | Med | 0.36 | 5.5 | 0.00 | Jun 26, 2025 | A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found. |
- risk 0.38cvss —epss 0.00
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers through Did you mean ...? suggestions embedded…
- risk 0.38cvss 5.8epss 0.00
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute…
- risk 0.38cvss 5.9epss 0.00
Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, leading to information exposure.
- risk 0.38cvss 5.8epss 0.00
An administrator could discover another account's credentials.
- risk 0.38cvss 5.8epss 0.00
MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available to unauthenticated users.
- risk 0.38cvss 5.3epss 0.03
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.
- risk 0.38cvss 5.9epss 0.01
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.
- risk 0.38cvss 5.9epss 0.00
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14.
- risk 0.38cvss 5.8epss 0.01
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this…
- risk 0.37cvss 5.7epss 0.01
Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 6.8epss 0.00
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes…
- risk 0.36cvss 5.5epss 0.00
Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly handle error messages and discloses sensitive password hash information when processing user authentication requests. This could allow a local attacker to…
- risk 0.36cvss 5.5epss 0.01
Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.