← Back
CWE-200

10,518 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,518)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netiq
1Identity Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or simi...Show more
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.Show less
1Ibm
2General Parallel File System
Spectrum Scale
Nov 21, 2024
Mar 2, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.
3Debian
DovecotUbuntu
3Debian Linux
DovecotUbuntu
Nov 21, 2024
Mar 2, 2018
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vuln...Show more
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.Show less
1Drupal
1Drupal
Nov 21, 2024
Mar 1, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerabilit...Show more
In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerability is mitigated by the fact that the comment system must be enabled and the attacker must have permission to post comments.Show less
1Opensuse
1Open Build Service
Nov 21, 2024
Mar 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
1Ibm
1Tririga Application Platform
Nov 21, 2024
Feb 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive information via vectors involving a database query. IBM X-Force ID: 111382.
2Debian
Limesurvey
2Debian Linux
Limesurvey
Jun 17, 2026
Feb 28, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.
1Synology
1Surveillance Station
Nov 21, 2024
Feb 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensiti...Show more
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.Show less
1
1Wireless Ip Camera 360
Nov 21, 2024
Feb 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Wireless IP Camera 360 devices. Attackers can read recordings by navigating to /mnt/idea0 or /mnt/idea1 on the SD memory card.
2Microsoft
Tivo
5Safedisc
Windows 7Windows 8+2 more
Jun 17, 2026
Feb 26, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCT...Show more
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool data.Show less
1Ibm
1Security Guardium Big Data Intelligence
Nov 21, 2024
Feb 26, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 136818.
1Apache
1Geode
Nov 21, 2024
Feb 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode l...Show more
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.Show less
1Netapp
2Oncommand Api Services
Service Level Manager
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected pas...Show more
All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected password is changed during every upgrade/installation no further action is required.Show less
1Synology
1Photo Station
Nov 21, 2024
Feb 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
1Christianwebministries
1Proclaim
Jun 17, 2026
Feb 22, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Feb 22, 2018
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 1383...Show more
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138377.Show less
1Ibm
1Security Identity Manager Virtual Appliance
Nov 21, 2024
Feb 21, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.
1Ibm
1Security Privileged Identity Manager
Nov 21, 2024
Feb 21, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.
1Ibm
1Security Identity Manager Virtual Appliance
Nov 21, 2024
Feb 21, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cook...Show more
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.Show less
1Ibm
1Tririga Application Platform
Nov 21, 2024
Feb 21, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force I...Show more
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786.Show less