CWE-550
Server-generated Error Message Containing Sensitive Information
Description
Certain conditions, such as network failure, will cause a server error message to be displayed.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40726 | Hig | 0.57 | 8.8 | 0.01 | Sep 12, 2023 | A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database. | ||
| CVE-2025-36419 | Med | 0.34 | 5.3 | 0.00 | Jan 20, 2026 | IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks against the system. | ||
| CVE-2023-5617 | Med | 0.34 | 5.3 | 0.00 | Feb 28, 2024 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered. | ||
| CVE-2025-62168 | Cri | 0.05 | 10.0 | 0.63 | Oct 17, 2025 | Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted… |
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database.
- risk 0.34cvss 5.3epss 0.00
IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks against the system.
- risk 0.34cvss 5.3epss 0.00
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.
- risk 0.05cvss 10.0epss 0.63
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted…