VYPR

CWE-550

Server-generated Error Message Containing Sensitive Information

VariantIncomplete

Description

Certain conditions, such as network failure, will cause a server error message to be displayed.

While error messages in and of themselves are not dangerous, per se, it is what an attacker can glean from them that might cause eventual problems.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (4)

  • CVE-2023-40726HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database.

  • CVE-2025-36419MedJan 20, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks against the system.

  • CVE-2023-5617MedFeb 28, 2024
    risk 0.34cvss 5.3epss 0.00

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.

  • CVE-2025-62168CriOct 17, 2025
    risk 0.05cvss 10.0epss 0.63

    Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted…