← Back
CWE-200

10,489 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,489)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fedoraproject
1Sssd
Nov 21, 2024
Dec 19, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could b...Show more
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.Show less
2Arm
Trustedfirmware
2Arm Trusted Firmware
Trusted Firmware A
Jun 5, 2026
Dec 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Dec 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes...Show more
An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.Show less
1Virustotal
1Yara
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine.
1Ibm
1Security Guardium
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser hist...Show more
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 124747. IBM X-Force ID: 124747.Show less
1Openstack
1Keystone
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is...Show more
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that should have an OpenStack Security AdvisoryShow less
1Google
1Rendertron
Nov 21, 2024
Dec 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.
1Designmodo
1Wp Maintenance Mode
Nov 21, 2024
Dec 14, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Dec 14, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-m...Show more
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.Show less
1Sonarsource
1Sonarqube
Nov 21, 2024
Dec 14, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs becaus...Show more
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field to non-administrator users. The attacker could use this information in subsequent attacks against the system.Show less
3Grafana
NetappRedhat
7Active Iq Performance Analytics Services
Ceph StorageEnterprise Linux Desktop+4 more
Nov 21, 2024
Dec 13, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
1Avantimarkets
1Market Card
Nov 21, 2024
Dec 13, 2018
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Di...Show more
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Disclosure. The vulnerability is due to lack of proper validation of the UPC bar code present on the MarketCard. An attacker could exploit this vulnerability by generating a copy of a customer's bar code. An exploit could allow the attacker to access all funds located within the MarketCard or allow unauthenticated disclosure of information.Show less
1Ibm
1Security Access Manager
Nov 21, 2024
Dec 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force...Show more
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 152021.Show less
1Ibm
1Security Access Manager
Nov 21, 2024
Dec 13, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 14970...Show more
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 149704.Show less
1Siemens
1Simatic Step 7 (tia Portal)
Nov 21, 2024
Dec 13, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwo...Show more
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwords. The vulnerability could be exploited by an attacker with local access to the project file. No user interaction is required to exploit the vulnerability. The vulnerability could allow the attacker to obtain certain passwords from the project. At the time of advisory publication no public exploitation of this vulnerability was known.Show less
1Apache
1Ofbiz
Jun 17, 2026
Dec 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests...Show more
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.Show less
1Opendental
1Opendental
Nov 21, 2024
Dec 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt. This allows the attacker to gain access to usernames, password hashes, p...Show more
Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt. This allows the attacker to gain access to usernames, password hashes, privilege levels, and more.Show less
1Ibm
1Bigfix Platform
Nov 21, 2024
Dec 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, refe...Show more
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 140763.Show less
1Ibm
1Bigfix Platform
Nov 21, 2024
Dec 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 140757.
1F5
16Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+13 more
Nov 21, 2024
Dec 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not h...Show more
On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.Show less