← Back
CWE-200

10,527 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,527)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Apr 27, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/...Show more
CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/dunzip.php, or /modules/FileManager/untgz.php.Show less
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Apr 27, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricte...Show more
In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricted access to the PHP file_get_contents function.Show less
1Cmsmadesimple
1Cms Made Simple
Nov 21, 2024
Apr 27, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.ph...Show more
In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.php to the upload/ directory.Show less
1Linuxfoundation
1Opendaylight
Nov 21, 2024
Apr 27, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
2Debian
Xen
2Debian Linux
Xen
Nov 21, 2024
Apr 27, 2018
N/A· v4
5.6 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as...Show more
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.Show less
1Ibm
1Campaign
Nov 21, 2024
Apr 27, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt
Nov 21, 2024
Apr 26, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.Show less
2Openstack
Redhat
2Openstack
Puppet Swift
Nov 21, 2024
Apr 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for...Show more
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.Show less
1Netiq
1Identity Manager
Nov 21, 2024
Apr 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
11234n
1Minicms
Nov 21, 2024
Apr 26, 2018
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.
11234n
1Minicms
Nov 21, 2024
Apr 26, 2018
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.
1Ibm
1Integrated Management Module Firmware
Nov 21, 2024
Apr 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to gen...Show more
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.Show less
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Apr 25, 2018
N/A· v4
4.1 MEDIUM· v3
1.5 LOW· v2
The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow local users to obtain sensitive information by leveraging root access. IBM X-Force ID: 90988.
3Canonical
DpdkRedhat
9Ceph Storage
Data Plane Development KitEnterprise Linux+6 more
Nov 21, 2024
Apr 24, 2018
N/A· v4
6.1 MEDIUM· v3
2.9 LOW· v2
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead t...Show more
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Apr 24, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (R...Show more
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) stores potentially sensitive information in a cache that could be read by authenticated users. IBM X-Force ID: 134915.Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Apr 24, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (R...Show more
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) contain an undisclosed vulnerability with the potential for information disclosure. IBM X-Force ID: 134820.Show less
1Lutron
1Quantum Bacnet Integration Firmware
Jun 17, 2026
Apr 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure.
1Ibm
2Sterling B2b Integrator
Sterling File Gateway
Nov 21, 2024
Apr 20, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.
1Ibm
2Security Identity Manager
Tivoli Identity Manager
Nov 21, 2024
Apr 20, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sen...Show more
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sensitive information by leveraging support for weak SSL ciphers. IBM X-Force ID: 96184.Show less
1Ibm
2Security Identity Manager
Tivoli Identity Manager
Nov 21, 2024
Apr 20, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intend...Show more
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via vectors related to server side LDAP queries. IBM X-Force ID: 96173.Show less