← Back
CWE-200

10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,459)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Sterling Selling And Fulfillment Foundation
May 13, 2026
Feb 1, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session...Show more
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.Show less
1Ibm
1Kenexa Lms
May 13, 2026
Feb 1, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
1Ibm
1Urbancode Deploy
May 13, 2026
Feb 1, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensi...Show more
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.
1Ibm
1Websphere Message Broker
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.
1Ibm
1Tivoli Storage Manager For Virtual Environments Data Protection For Vmware
May 13, 2026
Feb 1, 2017
N/A· v4
6.8 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.
1Ibm
1Infosphere Information Server
May 13, 2026
Feb 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine its contents.
1Ibm
1Security Privileged Identity Manager
May 13, 2026
Feb 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available to an authenticated user.
1Ibm
1Security Privileged Identity Manager
May 13, 2026
Feb 1, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit...Show more
IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
1Security Privileged Identity Manager
May 13, 2026
Feb 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission wi...Show more
IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information.Show less
1Ibm
6Maximo Asset Management
Maximo For AviationMaximo For Life Sciences+3 more
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.
1Ibm
3Security Access Manager
Security Access Manager For MobileSecurity Access Manager For Web
May 13, 2026
Feb 1, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser histo...Show more
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.Show less
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For MobileSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to...Show more
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
1Security Appscan Source
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
1Ibm
3Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 8.0 Firmware
May 13, 2026
Feb 1, 2017
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.