CWE-209
575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Openautomationsoftware 1Oas Platform Jun 17, 2026 Sep 5, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a d...Show more |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Aug 31, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 256015. |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Aug 31, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-force ID: 256014. |
1Phpjabbers 1Make An Offer Widget Jun 17, 2026 Aug 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling...Show more |
1Phpjabbers 1Ticket Support Script Jun 17, 2026 Aug 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling...Show more |
1Phpjabbers 1Event Booking Calendar Jun 17, 2026 Aug 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a...Show more |
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a bru...Show more |
User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a br...Show more |
User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a bru...Show more |
1Phpjabbers 1Yacht Listing Script Jun 17, 2026 Aug 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a b...Show more |
1Phpjabbers 1Hotel Booking System Jun 17, 2026 Aug 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a...Show more |
1Phpjabbers 1Restaurant Booking Script Jun 17, 2026 Aug 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabli...Show more |
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute...Show more |
1Phpjabbers 1Food Delivery Script Jun 17, 2026 Aug 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a b...Show more |
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. Thi...Show more |
e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.
|
Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin...Show more |
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future...Show more |
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user...Show more |
Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supports...Show more |