CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sophos 1Unified Threat Management Software May 6, 2026 Oct 3, 2016 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / sc...Show more |
1Sophos 1Unified Threat Management Software May 6, 2026 Oct 3, 2016 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications conf...Show more |
1Ibm 1Websphere Application Server May 6, 2026 Oct 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain se...Show more |
1Siemens 2Scalance M 800 Firmware Scalance S615 FirmwareMay 6, 2026 Sep 29, 2016 N/A· v4 4.0 MEDIUM· v3 4.3 MEDIUM· v2 The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to captur...Show more |
The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226. |
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors. |
SAP HANA DB 1.00.091.00.1418659308 allows remote attackers to obtain sensitive topology information via an unspecified HTTP request, aka SAP Security Note 2176128. |
1Ibm 1Tealeaf Customer Experience May 6, 2026 Sep 26, 2016 N/A· v4 4.9 MEDIUM· v3 2.6 LOW· v2 The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A bef...Show more |
1Ibm 1Security Privileged Identity Manager Virtual Appliance May 6, 2026 Sep 26, 2016 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify d...Show more |
1Ibm 1Security Privileged Identity Manager Virtual Appliance May 6, 2026 Sep 26, 2016 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document cont...Show more |
1Ibm 1Security Privileged Identity Manager Virtual Appliance May 6, 2026 Sep 26, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL. |
1Ibm 2Spectrum Control Tivoli Storage Productivity CenterMay 6, 2026 Sep 26, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL. |
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack. |
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors. |
3Debian GoogleNodejs3Chrome Debian LinuxNode.jsMay 6, 2026 Sep 25, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code. |
The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname. |
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted...Show more |
Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors. |
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation. |
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing...Show more |