VYPR

CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

BaseIncomplete

Description

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-170 · CAPEC-694

CVEs mapped to this weakness (378)

page 12 of 19
  • CVE-2024-49252MedOct 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6.

  • CVE-2024-9470MedOct 9, 2024
    risk 0.34cvss epss 0.00

    A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.

  • CVE-2024-3774MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.00

    aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.

  • CVE-2023-50959MedMar 31, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connected Enterprise Content Management system…

  • CVE-2023-41366MedNov 14, 2023
    risk 0.34cvss 5.3epss 0.01

    Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22,…

  • CVE-2023-37487MedAug 8, 2023
    risk 0.34cvss 5.3epss 0.01

    SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the…

  • CVE-2022-38710MedNov 3, 2022
    risk 0.34cvss 5.3epss 0.00

    IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.

  • CVE-2024-41781MedNov 22, 2024
    risk 0.33cvss 5.1epss 0.00

    IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains…

  • CVE-2023-34209MedOct 17, 2023
    risk 0.33cvss 5.0epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to obtain the absolute path via unencrypted VIEWSTATE parameter.

  • CVE-2025-59575MedOct 22, 2025
    risk 0.32cvss 4.9epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS: from n/a through <= 3.6.20.

  • CVE-2026-41459MedApr 22, 2026
    risk 0.31cvss 5.3epss 0.01

    Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the…

  • CVE-2025-8700MedAug 26, 2025
    risk 0.31cvss epss 0.00

    Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a debugger, read or modify the process memory, inject code in the…

  • CVE-2025-8597MedAug 26, 2025
    risk 0.31cvss epss 0.00

    MacVim's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a debugger, read or modify the process memory, inject code in the…

  • CVE-2024-12993MedDec 30, 2024
    risk 0.31cvss epss 0.00

    Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges.  After multiple attempts to contact the vendor we did not…

  • CVE-2024-45440MedAug 29, 2024
    risk 0.31cvss 5.3epss 0.09

    core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.

  • CVE-2025-6390MedJul 10, 2025
    risk 0.29cvss 4.4epss 0.00

    Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the…

  • CVE-2025-4662MedJul 10, 2025
    risk 0.29cvss 4.4epss 0.00

    Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server…

  • CVE-2025-2598MedMar 21, 2025
    risk 0.29cvss 5.5epss 0.00

    When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should…

  • CVE-2024-53683MedJan 17, 2025
    risk 0.29cvss 4.4epss 0.00

    A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use.

  • CVE-2022-20734MedMay 4, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit…