← Back
CWE-200

10,497 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,497)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Aug 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 befo...Show more
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain the email address of the reporter and assignee user of an issue despite the configured email visibility setting being set to hidden.Show less
1Ibm
2Platform Symphony
Spectrum Symphony
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information...Show more
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information. IBM X-Force ID: 146340.Show less
2Netapp
Openbsd
6Cloud Backup
Cn1610 FirmwareData Ontap Edge+3 more
Dec 18, 2025
Aug 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that t...Show more
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'Show less
2Openstack
Redhat
2Cinder
Openstack
Nov 21, 2024
Aug 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes...Show more
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.Show less
1Ibm
1Websphere Commerce
Nov 21, 2024
Aug 27, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenti...Show more
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.Show less
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
1Asustor
1Data Master
Nov 21, 2024
Aug 27, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
1Joomanager Project
1Joomanager
Nov 21, 2024
Aug 26, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=...Show more
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.Show less
1Seasofsolutions
1Ip Camera Firmware
Nov 21, 2024
Aug 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive information from the device.
1Seasofsolutions
1Ip Camera Firmware
Nov 21, 2024
Aug 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive information about the network configuration like the network SSID and...Show more
Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive information about the network configuration like the network SSID and password.Show less
1Ibm
1Websphere Application Server
Nov 21, 2024
Aug 24, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (J...Show more
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR375 authentication.Show less
1Jenkins
1Jenkins
Nov 21, 2024
Aug 23, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
Nov 21, 2024
Aug 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values usi...Show more
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.Show less
1Bloop
1Airmail 3
Nov 21, 2024
Aug 21, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" co...Show more
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" command with the "attachment_" prefix designate attachment parameters. If the value of an attachment parameter corresponds to an accessible file path, the file is attached to the outbound message. In addition, relative file paths are acceptable attachment parameter values. The handler can be invoked using any method that invokes the URL handler such as a hyperlink in an email. The user is not prompted when the handler processes the "send" command, thus leading to automatic transmission of an email with designated attachments from the target account to a target address.Show less
1Olacabs
1Ola Money
Nov 21, 2024
Aug 21, 2018
N/A· v4
7.5 HIGH· v3
2.6 LOW· v2
An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with accessibility permissions and the ability to read SMS messages, then the Forg...Show more
An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with accessibility permissions and the ability to read SMS messages, then the Forgot Password screen can be used to bypass authentication. NOTE: the vendor does not agree that this is a security issue requiring a fixShow less
1Geutebrueck
1Re Porter 16 Firmware
Nov 21, 2024
Aug 21, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP port 12003.
2Debian
Dropbear Ssh Project
2Debian Linux
Dropbear Ssh
Nov 21, 2024
Aug 21, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a simil...Show more
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.Show less
1Signal
1Signal Desktop
Nov 21, 2024
Aug 20, 2018
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
2Libvirt
Redhat
10Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
Nov 21, 2024
Aug 20, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.