CWE-209
575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Jan 4, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information |
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information |
1Reprisesoftware 1Reprise License Manager Jun 17, 2026 Dec 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is inv...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox...Show more |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 23, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in...Show more |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used i...Show more |
A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overl...Show more |
/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stored in the system. |
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furthe...Show more |
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furthe...Show more |
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the s...Show more |
1Ibm 1Edge Application Manager Jun 17, 2026 Sep 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941. |
1Cisco 12Catalyst Sd Wan Manager Sd Wan Vbond OrchestratorSd Wan Vmanage+9 moreJun 17, 2026 Sep 23, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attac...Show more |
1Ibm 1Security Secret Server Jun 17, 2026 Sep 14, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks ag...Show more |
Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credential...Show more |
Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder ex...Show more |
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL. |
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register...Show more |
A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a user invited to a group |