← Back
CWE-200

10,527 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,527)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dataiku
1Data Science Studio
Nov 21, 2024
May 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
1Myscada
1Mypro
Nov 21, 2024
May 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
May 28, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
1Werewolf Online Project
1Werewolf Online
Nov 21, 2024
May 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
1Fortinet
1Fortios
Nov 21, 2024
May 25, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via spec...Show more
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.Show less
1Trendmicro
4Antivirus+
Internet SecurityMaximum Security+1 more
Jun 17, 2026
May 25, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within p...Show more
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Ibm
1Storwize Unified V7000 Software
Nov 21, 2024
May 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. IBM X-Force ID: 140398.
2Canonical
Haproxy
2Haproxy
Ubuntu Linux
Nov 21, 2024
May 25, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, rel...Show more
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.Show less
1Ibm
1Urbancode Deploy
Nov 21, 2024
May 25, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.
1Moodle
1Moodle
Nov 21, 2024
May 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL.
1Ibm
1Tivoli Application Dependency Discovery Manager
Nov 21, 2024
May 24, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in w...Show more
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361.Show less
1Ibm
1Tivoli Application Dependency Discovery Manager
Nov 21, 2024
May 24, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct requ...Show more
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.Show less
1Citrix
1Xenmobile Server
Nov 21, 2024
May 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
1Jenkins
1Jenkins
Nov 21, 2024
May 22, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its sugge...Show more
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its suggestions, including the ones for which the current user does not have access to.Show less
1Joomla
1Joomla
Nov 21, 2024
May 22, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission.
1Magnicomp
1Sysinfo
Jun 17, 2026
May 21, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file...Show more
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information such as password hashes (/etc/shadow) or other secrets (such as log files or private keys) can be leaked to the attacker. The vulnerability has a confidentiality impact, but has no direct impact on system integrity or availability.Show less
1Adobe
1Digital Editions
Nov 21, 2024
May 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
1Redhat
1Tectonic
Nov 21, 2024
May 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an att...Show more
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure. Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges.Show less
1Ibm
8San Volume Controller Firmware
Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 more
Nov 21, 2024
May 17, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain the private key which could make intercepting GUI communications possible. IBM X-Force ID: 140396.Show less
1Ibm
8San Volume Controller Firmware
Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 more
Nov 21, 2024
May 17, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to obtain sensitive information that they should not have authorization to read. IBM X-Force ID: 140395.Show less