VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (600)

page 9 of 30
  • CVE-2019-4619MedMar 16, 2020
    risk 0.36cvss 5.5epss 0.00

    IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.

  • CVE-2026-43630MedAug 6, 2026
    risk 0.35cvss 6.5epss 0.00

    llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the allocated cells array. Attackers can craft a…

  • CVE-2025-65995MedFeb 21, 2026
    risk 0.35cvss 6.5epss 0.01

    When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to…

  • CVE-2025-9977MedNov 18, 2025
    risk 0.35cvss epss 0.02

    Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an unauthenticated attacker to perform DoS attacks. SQL injection attacks might also be feasible, although so far creating a working…

  • CVE-2025-43776MedSep 9, 2025
    risk 0.35cvss 5.4epss 0.00

    A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through…

  • CVE-2024-35112MedJan 25, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2024-39737MedJul 15, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: …

  • CVE-2023-50953MedJun 30, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force ID: 275775.

  • CVE-2024-21619MedJan 25, 2024
    risk 0.35cvss 5.3epss 0.01

    A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access…

  • CVE-2024-21313MedJan 9, 2024
    risk 0.35cvss 5.3epss 0.01

    Windows TCP/IP Information Disclosure Vulnerability

  • CVE-2023-47703MedDec 20, 2023
    risk 0.35cvss 5.3epss 0.01

    IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.

  • CVE-2023-42013MedDec 20, 2023
    risk 0.35cvss 5.3epss 0.01

    IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks…

  • CVE-2023-31048MedDec 12, 2023
    risk 0.35cvss 5.3epss 0.01

    The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.

  • CVE-2023-43021MedDec 1, 2023
    risk 0.35cvss 5.3epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 266167.

  • CVE-2023-35009MedAug 16, 2023
    risk 0.35cvss 5.3epss 0.01

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-Force ID: 257703.

  • CVE-2023-26051MedMar 2, 2023
    risk 0.35cvss 6.5epss 0.01

    Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information like user email address in…

  • CVE-2023-0655MedFeb 14, 2023
    risk 0.35cvss 5.3epss 0.01

    SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses.

  • CVE-2022-22449MedDec 24, 2022
    risk 0.35cvss 5.3epss 0.01

    IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: …

  • CVE-2022-39315MedOct 25, 2022
    risk 0.35cvss 6.5epss 0.01

    Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only be exploited for targeted attacks…

  • CVE-2021-39086MedAug 16, 2022
    risk 0.35cvss 5.3epss 0.01

    IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further…