VYPR

CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

BaseIncomplete

Description

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-170 · CAPEC-694

CVEs mapped to this weakness (378)

page 2 of 19
  • CVE-2025-4364HigMay 20, 2025
    risk 0.57cvss epss 0.00

    The affected products could allow an unauthenticated attacker to access system information that could enable further access to sensitive files and obtain administrative credentials.

  • CVE-2024-8313HigMar 25, 2025
    risk 0.57cvss epss 0.00

    An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration…

  • CVE-2025-0061HigJan 14, 2025
    risk 0.57cvss 8.7epss 0.01

    SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.

  • CVE-2024-39675HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.10), RUGGEDCOM RP110 (All versions < V4.3.10), RUGGEDCOM RP110NC (All versions < V4.3.10), RUGGEDCOM RS400 (All versions < V4.3.10), RUGGEDCOM RS400NC (All…

  • CVE-2026-28698HigJul 23, 2026
    risk 0.56cvss 8.6epss 0.00

    Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.

  • CVE-2026-42047HigMay 7, 2026
    risk 0.56cvss 8.6epss 0.00

    Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host…

  • CVE-2026-24222HigApr 28, 2026
    risk 0.56cvss 8.6epss 0.00

    NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly…

  • CVE-2024-12367HigSep 16, 2025
    risk 0.56cvss 8.6epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing. This issue affects Vega Master: from v.1.12.35 through 20250916.  NOTE: The vendor did not inform about the completion of the…

  • CVE-2022-28651HigApr 5, 2022
    risk 0.55cvss 8.4epss 0.00

    In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields

  • CVE-2021-31955MedKEVJun 8, 2021
    risk 0.54cvss 5.5epss 0.81

    Windows Kernel Information Disclosure Vulnerability

  • CVE-2025-13691HigFeb 17, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.

  • CVE-2025-9986HigFeb 11, 2026
    risk 0.53cvss 8.2epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information Systems Ltd. Co. DIGIKENT allows Excavation. This issue affects DIGIKENT: through 13092025.

  • CVE-2025-11151HigOct 21, 2025
    risk 0.53cvss 8.2epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beyaz Bilgisayar Software Design Industry and Trade Ltd. Co. CityPLus allows Detect Unpublicized Web Pages. This issue affects…

  • CVE-2026-34413HigApr 22, 2026
    risk 0.52cvss 8.6epss 0.03

    Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to…

  • CVE-2025-32792HigApr 18, 2025
    risk 0.50cvss epss 0.01

    SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior to version 1.12.0, web pages and web extensions using `ses` and the Compartment API to evaluate third-party code in an isolated execution…

  • CVE-2024-45549HigApr 7, 2025
    risk 0.50cvss 7.7epss 0.00

    Information disclosure while creating MQ channels.

  • CVE-2025-22222HigJan 30, 2025
    risk 0.50cvss 7.7epss 0.01

    VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.

  • CVE-2022-20664HigJun 15, 2022
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight…

  • CVE-2026-52694HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

  • CVE-2026-49068HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.