← Back
CWE-200

10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,521)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Business Process Manager
Business Process Manager Enterprise Service Bus
Nov 21, 2024
Mar 30, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.
1Ibm
3Business Process Manager
Business Process Manager Enterprise Service BusWebsphere
Nov 21, 2024
Mar 30, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.
1Ibm
1Security Privileged Identity Manager
Nov 21, 2024
Mar 30, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134...Show more
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.Show less
1Google
1Android
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris_vidioc_s_ext_ctrls i...Show more
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris_vidioc_s_ext_ctrls ioctl, it will print kernel address data. A user could set it to an arbitrary kernel address, hence information disclosure (for kernel) could occur.Show less
2Cloudfoundry
Pivotal Software
2Cf Release
Cloud Foundry Elastic Runtime
Nov 21, 2024
Mar 29, 2018
N/A· v4
9.6 CRITICAL· v3
4.0 MEDIUM· v2
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (...Show more
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.Show less
1Cloudfoundry
2Cf Deployment
Garden Runc Release
Nov 21, 2024
Mar 29, 2018
N/A· v4
8.8 HIGH· v3
3.5 LOW· v2
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using thos...Show more
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.Show less
1Reviewboard
1Review Board
Nov 21, 2024
Mar 29, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from reposi...Show more
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.Show less
1Opera
1Opera Browser
Jun 17, 2026
Mar 28, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN reque...Show more
In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.Show less
1Wanscam
1Hw0021 Firmware
Nov 21, 2024
Mar 28, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username and password via an ONVIF GetSnapshotUri request.
1Netiq
1Identity Manager
Jun 17, 2026
Mar 28, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
1Qnap
1Qts
Nov 21, 2024
Mar 27, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
1Avolvesoftware
1Projectdox
Nov 21, 2024
Mar 27, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
1Avolvesoftware
1Projectdox
Nov 21, 2024
Mar 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.
1Avolvesoftware
1Projectdox
Nov 21, 2024
Mar 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct access token.
2Arm
Intel
209Atom C
Atom EAtom X3+206 more
Jun 17, 2026
Mar 27, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demons...Show more
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.Show less
1Ibm
14Change And Configuration Management Database
Control DeskMaximo Asset Management+11 more
Nov 21, 2024
Mar 27, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticat...Show more
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.Show less
1Cisco
1Spark Hybrid Calendar Service
Nov 21, 2024
Mar 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The a...Show more
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to conduct additional reconnaissance attacks leading to the disclosure of sensitive customer data. The vulnerability exists in the auto discovery phase because an unencrypted HTTP request is made due to requirements for implementing the Hybrid Calendar service. An attacker could exploit this vulnerability by monitoring the unencrypted traffic on the network. An exploit could allow the attacker to access sensitive customer data belonging to Office365 users, such as email and calendar events. Cisco Bug IDs: CSCvg35593.Show less
1Ibm
1Capacity Management Analytics
Nov 21, 2024
Mar 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107863.
1Ibm
1Capacity Management Analytics
Nov 21, 2024
Mar 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107862.
1Ibm
1Capacity Management Analytics
Nov 21, 2024
Mar 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.