← Back
CWE-200

10,499 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,499)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Jul 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719.
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Jul 6, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.
1Ibm
2Rational Collaborative Lifecycle Management
Rational Quality Manager
Nov 21, 2024
Jul 6, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124357.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jul 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitiv...Show more
Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action to api/tasks.Show less
1Sylabs
1Singularity
Nov 21, 2024
Jul 5, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few s...Show more
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.Show less
1Fortinet
1Fortios
Jun 17, 2026
Jul 5, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single...Show more
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.Show less
1Onefilecms
1Onefilecms
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file.
1Schneider Electric
1U.motion Builder
Jun 17, 2026
Jul 3, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.
1Medtronic
12090 Carelink Programmer Firmware
May 22, 2025
Jul 3, 2018
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affect...Show more
Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affected products initially establish an encapsulated IP-based VPN connection to a Medtronic-hosted update network. Once the VPN is established, it makes a request to a HTTP (non-TLS) server across the VPN for updates, which responds and provides any available updates. The programmer-side (client) service responsible for this HTTP request does not check to ensure it is still connected to the VPN before making the HTTP request. Thus, an attacker could cause the VPN connection to terminate (through various methods and attack points) and intercept the HTTP request, responding with malicious updates via a man-in-the-middle attack. The affected products do not verify the origin or integrity of these updates, as it insufficiently relied on the security of the VPN. An attacker with remote network access to the programmer could influence these communications.Show less
2Debian
Xen
2Debian Linux
Xen
Nov 21, 2024
Jul 2, 2018
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrator...Show more
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may be able to write to supposedly read-only disk images. Only emulated SCSI disks (specified as "sd" in the libxl disk configuration, or an equivalent) are affected. IDE disks ("hd") are not affected (because attempts to make them readonly are rejected). Additionally, CDROM devices (that is, devices specified to be presented to the guest as CDROMs, regardless of the nature of the backing storage on the host) are not affected; they are always read only. Only systems using qemu-xen (rather than qemu-xen-traditional) as the device model version are vulnerable. Only systems using libxl or libxl-based toolstacks are vulnerable. (This includes xl, and libvirt with the libxl driver.) The vulnerability is present in Xen versions 4.7 and later. (In earlier versions, provided that the patch for XSA-142 has been applied, attempts to create read only disks are rejected.) If the host and guest together usually support PVHVM, the issue is exploitable only if the malicious guest administrator has control of the guest kernel or guest kernel command line.Show less
1Phpwcms
1Phpwcms
Nov 21, 2024
Jun 30, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
1Zohocorp
5Firewall Analyzer
Manageengine Netflow AnalyzerManageengine Network Configuration Manager+2 more
Nov 21, 2024
Jun 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161,...Show more
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server without login by sending a specially crafted request to the server with the operation=copyfile&fileName= substring.Show less
1Northernnep
1Northern Electric & Power Inverter Firmware
Nov 21, 2024
Jun 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI.
1Pharoscontrols
1Pharos Firmware
Nov 21, 2024
Jun 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/log.lsp URI.
1Bwssystems
1Ha Bridge
Nov 21, 2024
Jun 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI.
1Electroind
1Gaugetech Nexus Firmware
Nov 21, 2024
Jun 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.
1Flir
1Brickstream 2300 Firmware
Nov 21, 2024
Jun 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or basic.html#datadelivery URI.
1Ibm
1Websphere Application Server
Nov 21, 2024
Jun 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.
1Apache
1Pluto
Nov 21, 2024
Jun 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided...Show more
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.Show less
1Tibco
2Spotfire Analytics Platform For Aws
Spotfire Server
Jun 17, 2026
Jun 27, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, i...Show more
The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Server: versions up to and including 7.8.1; 7.9.0; 7.10.0; 7.11.0; 7.12.0.Show less