CWE-209
575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 9Collaborative Lifecycle Management Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against t...Show more |
2Debian Rubyonrails3Actionpack Page Caching Debian LinuxRailsJun 17, 2026 May 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input. |
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the s...Show more |
1Ibm 1Security Identity Manager Jun 17, 2026 May 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks agai...Show more |
1Ibm 1Security Identity Manager Jun 17, 2026 May 20, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks agai...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJul 9, 2026 May 16, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attacker...Show more |
1Ibm 1Qradar User Behavior Analytics Jun 17, 2026 May 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in f...Show more |
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload. |
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior...Show more |
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path. |
1Mendix 1Database Replication Jun 17, 2026 May 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions...Show more |
A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the use...Show more |
IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against t...Show more |
1Node Etsy Client Project 1Node Etsy Client Jun 17, 2026 Apr 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-client v0.3.0 and later. |
1Django Registration Project 1Django Registration Jun 17, 2026 Apr 1, 2021 N/A· v4 2.6 LOW· v3 3.5 LOW· v2 django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to...Show more |
2Postgresql Redhat3Enterprise Linux PostgresqlSoftware CollectionsJun 17, 2026 Apr 1, 2021 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under so...Show more |
4Netapp OracleQuarkus+1 more4Communications Cloud Native Core Console Oncommand InsightQuarkus+1 moreJun 17, 2026 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or q...Show more |
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages. |
An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project. |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Feb 26, 2021 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure. |