CWE-200
10,527 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,527)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Apr 27, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/...Show more |
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Apr 27, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricte...Show more |
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Apr 27, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.ph...Show more |
1Linuxfoundation 1Opendaylight Nov 21, 2024 Apr 27, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions. |
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as...Show more |
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154. |
2Ovirt Redhat2Enterprise Virtualization OvirtNov 21, 2024 Apr 26, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more |
2Openstack Redhat2Openstack Puppet SwiftNov 21, 2024 Apr 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for...Show more |
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. |
mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field. |
mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article. |
1Ibm 1Integrated Management Module Firmware Nov 21, 2024 Apr 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to gen...Show more |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Apr 25, 2018 N/A· v4 4.1 MEDIUM· v3 1.5 LOW· v2 The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow local users to obtain sensitive information by leveraging root access. IBM X-Force ID: 90988. |
3Canonical DpdkRedhat9Ceph Storage Data Plane Development KitEnterprise Linux+6 moreNov 21, 2024 Apr 24, 2018 N/A· v4 6.1 MEDIUM· v3 2.9 LOW· v2 The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead t...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreNov 21, 2024 Apr 24, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (R...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreNov 21, 2024 Apr 24, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (R...Show more |
1Lutron 1Quantum Bacnet Integration Firmware Jun 17, 2026 Apr 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure. |
1Ibm 2Sterling B2b Integrator Sterling File GatewayNov 21, 2024 Apr 20, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072. |
1Ibm 2Security Identity Manager Tivoli Identity ManagerNov 21, 2024 Apr 20, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sen...Show more |
1Ibm 2Security Identity Manager Tivoli Identity ManagerNov 21, 2024 Apr 20, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intend...Show more |