← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sophos
1Unified Threat Management Software
May 6, 2026
Oct 3, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / sc...Show more
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.Show less
1Sophos
1Unified Threat Management Software
May 6, 2026
Oct 3, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications conf...Show more
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.Show less
1Ibm
1Websphere Application Server
May 6, 2026
Oct 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain se...Show more
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.Show less
1Siemens
2Scalance M 800 Firmware
Scalance S615 Firmware
May 6, 2026
Sep 29, 2016
N/A· v4
4.0 MEDIUM· v3
4.3 MEDIUM· v2
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to captur...Show more
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.Show less
1Sap
1Trex
May 6, 2026
Sep 27, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.
1Huawei
1Fusioncompute
May 6, 2026
Sep 26, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Sap
1Hana Db
May 6, 2026
Sep 26, 2016
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP HANA DB 1.00.091.00.1418659308 allows remote attackers to obtain sensitive topology information via an unspecified HTTP request, aka SAP Security Note 2176128.
1Ibm
1Tealeaf Customer Experience
May 6, 2026
Sep 26, 2016
N/A· v4
4.9 MEDIUM· v3
2.6 LOW· v2
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A bef...Show more
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to discover component passwords via unspecified vectors.Show less
1Ibm
1Security Privileged Identity Manager Virtual Appliance
May 6, 2026
Sep 26, 2016
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify d...Show more
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.Show less
1Ibm
1Security Privileged Identity Manager Virtual Appliance
May 6, 2026
Sep 26, 2016
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document cont...Show more
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Ibm
1Security Privileged Identity Manager Virtual Appliance
May 6, 2026
Sep 26, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
1Ibm
2Spectrum Control
Tivoli Storage Productivity Center
May 6, 2026
Sep 26, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.
1Ibm
1Connections
May 6, 2026
Sep 26, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
1Ibm
1Security Guardium
May 6, 2026
Sep 26, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
3Debian
GoogleNodejs
3Chrome
Debian LinuxNode.js
May 6, 2026
Sep 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname.
1Apple
3Iphone Os
ItunesSafari
May 6, 2026
Sep 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted...Show more
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.Show less
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing...Show more
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.Show less