VYPR

CWE-213

Exposure of Sensitive Information Due to Incompatible Policies

BaseDraft

Description

The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (33)

page 2 of 2
  • CVE-2022-33696MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

  • CVE-2022-33694MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.

  • CVE-2022-33692MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

  • CVE-2024-49827LowAug 18, 2025
    risk 0.24cvss 3.7epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.

  • CVE-2023-5117LowDec 25, 2024
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

  • CVE-2025-52603LowFeb 20, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.

  • CVE-2025-32791MedApr 16, 2025
    risk 0.21cvss 4.3epss 0.00

    The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permission policy installed…

  • CVE-2022-28794LowJun 7, 2022
    risk 0.14cvss 2.2epss 0.00

    Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

  • CVE-2022-30728LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2022-30714LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2026-56538LowJul 27, 2026
    risk 0.00cvss 3.5epss 0.00

    An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

  • CVE-2026-6280MedJul 8, 2026
    risk 0.00cvss 6.5epss 0.00

    Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was…

  • CVE-2019-1010283HigJul 17, 2019
    risk 0.00cvss 7.5epss 0.01

    Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. The impact is: Loss of Confidentiality. The component is: function data_on_connection() in src/callback.c. The attack vector is: network…