← Back
CWE-200

10,373 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,373)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Unified Computing System
Apr 29, 2026
Oct 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication pr...Show more
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffing the network, aka Bug ID CSCtr72970.Show less
1Xen
1Xen
Apr 29, 2026
Oct 17, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive in...Show more
The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.Show less
1Hp
1Service Manager
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP Service Manager 9.30 through 9.32 allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Hp
2Imc Service Operation Management Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1647.
1Symantec
1Management Platform
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' i...Show more
The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about package-server access, or cause a denial of service, by leveraging knowledge of this key.Show less
1Hp
20Color Laserjet Cm4540
Color Laserjet Cm4540fColor Laserjet Cm4540fskm+17 more
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
1.5 LOW· v2
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read im...Show more
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors.Show less
2Emerson
Enea
4Dl 8000 Remote Terminal Unit
OseRoc 800 Remote Terminal Unit+1 more
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadc...Show more
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device presence by listening for broadcast traffic.Show less
1Openstack
1Python Keystoneclient
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
1Xen
1Xen
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values use...Show more
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.Show less
1Xen
1Xen
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
1.5 LOW· v2
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to...Show more
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.Show less
1Ibm
1Maximo Asset Management
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.
1Ibm
1Maximo Asset Management
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Xen
1Xen
Apr 29, 2026
Sep 30, 2013
N/A· v4
N/A· v3
1.2 LOW· v2
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching othe...Show more
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.Show less
2Jgroups
Redhat
2Jboss Enterprise Application Platform
Jgroup
Apr 29, 2026
Sep 28, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid crede...Show more
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.Show less
1Open Xchange
1Open Xchange Appsuite
Apr 29, 2026
Sep 25, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 allows remote attackers to obtain sensitive information about (1) runtime activity, (2) network configuration, (3)...Show more
The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 allows remote attackers to obtain sensitive information about (1) runtime activity, (2) network configuration, (3) user sessions, (4) the memcache interface, and (5) the REST interface via API calls such as a hazelcast/rest/cluster/ call, a different vulnerability than CVE-2013-5200.Show less
1Open Xchange
1Open Xchange Appsuite
Apr 29, 2026
Sep 25, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remo...Show more
The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remote attackers to obtain access by sending network traffic from an unintended location, a different vulnerability than CVE-2013-5200.Show less
1Ibm
4Data Studio Web Console
Db2 Recovery ExpertInfosphere Optim Configuration Manager+1 more
Apr 29, 2026
Sep 25, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allow...Show more
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.Show less
1Freebsd
1Freebsd
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to obtain sensitive information (kernel memor...Show more
The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to obtain sensitive information (kernel memory) via a length greater than the length of the file.Show less
1Cisco
1Prime Data Center Network Manager
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External...Show more
Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCud80148.Show less
1Cisco
1Prime Data Center Network Manager
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCue77029.