CWE-209
575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives out for each type of user on the Login form. For "Incorrect User" - it gives an error "The applicati...Show more |
IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks a...Show more |
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used i...Show more |
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informatio...Show more |
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informatio...Show more |
UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php. |
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4...Show more |
2Elastic Oracle2Communications Cloud Native Core Automated Test Suite ElasticsearchJun 17, 2026 Jul 21, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in...Show more |
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks...Show more |
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks...Show more |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks again...Show more |
1Siemens 1Teamcenter Active Workspace Jun 17, 2026 Jul 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). The affec...Show more |
1Nextcloud 1Nextcloud Server Jun 17, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to th...Show more |
1Ibm 1Guardium Data Encryption Jun 17, 2026 Jul 7, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attac...Show more |
1Ibm 1Guardium Data Encryption Jun 17, 2026 Jun 28, 2021 N/A· v4 4.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attac...Show more |
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 re...Show more |
1White Shark Systems Project 1White Shark Systems Jun 17, 2026 Jun 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability. |
1Zohocorp 1Manageengine Servicedesk Plus Msp Jun 17, 2026 Jun 16, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732. |
1Netapp 1E Series Santricity Os Controller Jun 17, 2026 Jun 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging whi...Show more |
1Checkpoint 1Ssl Network Extender Jun 17, 2026 Jun 8, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access. |