CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Linux2Android Linux KernelMay 13, 2026 Feb 8, 2017 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderat...Show more |
NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access. |
NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors. |
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors. |
NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified vectors. |
1Ibm 2Security Key Lifecycle Manager Tivoli Key Lifecycle ManagerMay 13, 2026 Feb 7, 2017 N/A· v4 4.0 MEDIUM· v3 2.1 LOW· v2 IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system. |
1Ibm 2Security Key Lifecycle Manager Tivoli Key Lifecycle ManagerMay 13, 2026 Feb 7, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data. |
1Ibm 2Security Key Lifecycle Manager Tivoli Key Lifecycle ManagerMay 13, 2026 Feb 7, 2017 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user. |
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file. |
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read loc...Show more |
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses. |
Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances...Show more |
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not...Show more |
1Emc 1Powerpath Virtual Appliance May 13, 2026 Feb 3, 2017 N/A· v4 6.4 MEDIUM· v3 6.0 MEDIUM· v2 EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users...Show more |
1Ibm 1Security Key Lifecycle Manager May 13, 2026 Feb 2, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerab...Show more |
1Ibm 1Security Key Lifecycle Manager May 13, 2026 Feb 2, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. |
1Ibm 1Dashboard Application Services Hub May 13, 2026 Feb 2, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensit...Show more |
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser histor...Show more |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system. |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user. |