← Back
CWE-209

575 CVEs • Abstraction: Base • Likelihood of Exploit: High

Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

JSON object

Loading...

CVEs (575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netapp
1Ontap Mediator
Jun 17, 2026
Dec 21, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to enumerate URLs via REST API.
1Ibm
1Security Guardium Key Lifecycle Manager
Jun 17, 2026
Dec 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further...Show more
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.Show less
1Ibm
1Urbancode Deploy
Jun 17, 2026
Dec 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the brows...Show more
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 265510.Show less
1Wso2
1Api Manager
Jun 17, 2026
Dec 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.
1Kaifa
1Webitr Attendance System
Jun 17, 2026
Dec 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.
1Ibm
3Virtualization Engine Ts7760 3957 Vec Firmware
Virtualization Engine Ts7770 3948 Ved FirmwareVirtualization Engine Ts7770 3957 Ved Firmware
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This info...Show more
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 272652.Show less
1Opcfoundation
1Ua .netstandard
Jun 17, 2026
Dec 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.
1Jupyter
1Jupyter Server
Jun 17, 2026
Dec 4, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an authen...Show more
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an authenticated user include traceback information, which can include path information. There is no known mechanism by which to trigger these errors without authentication, so the paths revealed are not considered particularly sensitive, given that the requesting user has arbitrary execution permissions already in the same environment. A fix has been introduced in commit `0056c3aa52` which no longer includes traceback information in JSON error responses. For compatibility, the traceback field is present, but always empty. This commit has been included in version 2.11.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Dec 1, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks...Show more
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 266167. Show less
1Pimcore
1Admin Classic Bundle
Jun 17, 2026
Nov 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain vulnerabilitie...Show more
The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain vulnerabilities, such as using the load_file() (within a SQL Injection) query to view the page source, require the attacker to have the full path to the file they wish to view. In the case of pimcore, the fopen() function here doesn't have an error handle when the file doesn't exist on the server so the server response raises the full path "fopen(/var/www/html/var/tmp/export-{ uniqe id}.csv)". This issue has been patched in commit `10d178ef771` which has been included in release version 1.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.
1Codeigniter
1Codeigniter
Jun 17, 2026
Oct 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential i...Show more
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked. Version 4.4.3 contains a patch. As a workaround, replace `ini_set('display_errors', '0')` with `ini_set('display_errors', 'Off')` in `app/Config/Boot/production.php`.Show less
1Ibm
1Security Verify Privilege On Premises
Jun 17, 2026
Oct 17, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further...Show more
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454. Show less
1Grafana
1Google Sheets
Jun 17, 2026
Oct 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did n...Show more
Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source. This vulnerability was fixed in version 1.2.2. Show less
1Sap
1S/4hana
Jun 17, 2026
Oct 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
2Redhat
Squareup
2A Mq Streams
Okhttp
Jun 23, 2026
Sep 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an a...Show more
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.Show less
1Juplink
1Rx4 1500 Firmware
Jun 17, 2026
Sep 22, 2023
N/A· v4
8.8 HIGH· v3
7.7 HIGH· v2
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via re...Show more
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint. Show less
1Siemens
1Qms Automotive
Jun 17, 2026
Sep 12, 2023
N/A· v4
4.0 MEDIUM· v3
N/A· v2
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an att...Show more
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an attacker to enumerate usernames, and identify valid usernames.Show less
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Sep 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low imp...Show more
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's availability or integrity. Show less
1Apache
1Superset
Jun 17, 2026
Sep 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.