CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Description
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-170 · CAPEC-694
CVEs mapped to this weakness (406)
page 5 of 21| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4237 | Hig | 0.47 | 7.3 | 0.00 | Oct 4, 2023 | A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality,… | ||
| CVE-2026-80118 | Hig | 0.46 | 7.1 | 0.00 | Sep 4, 2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no… | ||
| CVE-2026-7864 | Med | 0.46 | — | 0.17 | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information. | ||
| CVE-2025-47378 | Hig | 0.46 | 7.1 | 0.00 | Mar 2, 2026 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. | ||
| CVE-2025-55131 | Hig | 0.46 | 7.1 | 0.04 | Jan 20, 2026 | A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like… | ||
| CVE-2024-8687 | Hig | 0.46 | 7.1 | 0.00 | Sep 11, 2024 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end… | ||
| CVE-2025-66599 | Med | 0.45 | — | 0.00 | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displayed on web pages. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS… | ||
| CVE-2025-34156 | Med | 0.45 | — | 0.00 | Oct 23, 2025 | Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information… | ||
| CVE-2026-22537 | — | Med | 0.44 | — | 0.00 | Jan 7, 2026 | The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker. | |
| CVE-2025-47319 | Med | 0.44 | 6.7 | 0.00 | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | ||
| CVE-2025-46421 | Med | 0.44 | 6.8 | 0.01 | Apr 24, 2025 | A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect. | ||
| CVE-2022-34458 | Med | 0.43 | 6.6 | 0.00 | Feb 1, 2023 | Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability… | ||
| CVE-2025-33141 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment. | ||
| CVE-2026-27553 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2026 | A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes. | ||
| CVE-2026-76968 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure.… | ||
| CVE-2024-58375 | Hig | 0.42 | 7.5 | 0.00 | Aug 16, 2026 | OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration… | ||
| CVE-2026-66444 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||
| CVE-2026-6373 | Med | 0.42 | 6.5 | 0.00 | Aug 10, 2026 | Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026. | ||
| CVE-2026-48878 | Med | 0.42 | 6.5 | 0.00 | Jun 15, 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions. | ||
| CVE-2026-42660 | Med | 0.42 | 6.5 | 0.00 | Jun 15, 2026 | Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. |
- risk 0.47cvss 7.3epss 0.00
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality,…
- risk 0.46cvss 7.1epss 0.00
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no…
- risk 0.46cvss —epss 0.17
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
- risk 0.46cvss 7.1epss 0.00
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
- risk 0.46cvss 7.1epss 0.04
A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like…
- risk 0.46cvss 7.1epss 0.00
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end…
- risk 0.45cvss —epss 0.00
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displayed on web pages. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS…
- risk 0.45cvss —epss 0.00
Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information…
- risk 0.44cvss —epss 0.00
The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker.
- risk 0.44cvss 6.7epss 0.00
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
- risk 0.44cvss 6.8epss 0.01
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.
- risk 0.43cvss 6.6epss 0.00
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability…
- risk 0.42cvss 6.5epss 0.00
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
- risk 0.42cvss 6.5epss 0.01
A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.
- risk 0.42cvss 6.5epss 0.00
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure.…
- risk 0.42cvss 7.5epss 0.00
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration…
- risk 0.42cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
- risk 0.42cvss 6.5epss 0.00
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.
- risk 0.42cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.