← Back
CWE-209

575 CVEs • Abstraction: Base • Likelihood of Exploit: High

Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

JSON object

Loading...

CVEs (575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wftpserver
1Wing Ftp Server
Jun 17, 2026
Jul 10, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
1Ibm
1Analytics Content Hub
Jun 17, 2026
Jul 10, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be used in reconnaissance to gather information for future attacks from a d...Show more
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be used in reconnaissance to gather information for future attacks from a detailed technical error message.Show less
1Ibm
1Analytics Content Hub
Jun 17, 2026
Jul 10, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
1Quiter
1Quiter Gateway
Jun 17, 2026
Jul 8, 2025
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to send malformed payloads to generate error messages containing sensitive information.
2Infinispan
Redhat
4Data Grid
InfinispanJboss Enterprise Application Platform+1 more
Jun 17, 2026
Jun 26, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a co...Show more
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.Show less
1Digitaldruid
1Hoteldruid
Jul 9, 2026
Jun 20, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attac...Show more
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.Show less
-
-
Jun 17, 2026
Jun 6, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocati...Show more
Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocation._appendSourceDesc` method allows up to 500 bytes of unintended memory content to be included in exception messages. When parsing JSON from a byte array with an offset and length, the exception message incorrectly reads from the beginning of the array instead of the logical payload start. This results in possible information disclosure in systems using pooled or reused buffers, like Netty or Vert.x. This issue was silently fixed in jackson-core version 2.13.0, released on September 30, 2021, via PR #652. All users should upgrade to version 2.13.0 or later. If upgrading is not immediately possible, applications can mitigate the issue by disabling exception message exposure to clients to avoid returning parsing exception messages in HTTP responses and/or disabling source inclusion in exceptions to prevent Jackson from embedding any source content in exception messages, avoiding leakage.Show less
1Ibm
1Verify Identity Access Digital Credentials
Jun 17, 2026
Jun 6, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in fu...Show more
IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.Show less
1Ibm
1Security Guardium
Jun 17, 2026
May 28, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the...Show more
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.Show less
-
-
Jun 17, 2026
May 26, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine whether a username is valid or not, allowi...Show more
User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine whether a username is valid or not, allowing a brute force attack on valid usernames.Show less
1Synck
1Mailform Pro Cgi
Jun 17, 2026
May 26, 2025
6.3 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the c...Show more
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.Show less
-
-
Jun 17, 2026
May 12, 2025
N/A· v4
5.8 MEDIUM· v3
N/A· v2
An administrator could discover another account's credentials.
2Hashicorp
Openbao
2Openbao
Vault
Jun 17, 2026
May 2, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operati...Show more
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.Show less
1Fortra
1Goanywhere Managed File Transfer
Jun 17, 2026
Apr 28, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This iss...Show more
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.Show less
1Zte
1Zxcloud Goldendb
Jun 17, 2026
Apr 27, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 23, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the s...Show more
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.Show less
1Cisco
1Nexus Dashboard
Jun 17, 2026
Apr 16, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker...Show more
A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow an attacker to determine which usernames are valid LDAP user accounts.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Apr 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get t...Show more
An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."Show less
1Vcita
2Online Booking & Scheduling Calendar
Online Booking & Scheduling Calendar For Wordpress By Vcita
Jun 17, 2026
Apr 4, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Retrieve Embedded Sensitive Data.This issu...Show more
Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Retrieve Embedded Sensitive Data.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5.Show less
1Hcltech
1Traveler
Jun 17, 2026
Apr 3, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could ex...Show more
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.Show less