CWE-209
575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a differ...Show more |
1Ibm 10Control Desk Maximo Asset ManagementMaximo For Aviation+7 moreJun 17, 2026 Oct 9, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554. |
1Ibm 1Websphere Application Server Jun 17, 2026 Oct 3, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177. |
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293. |
1Dell 1Bsafe Micro Edition Suite Jun 17, 2026 Sep 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 RSA BSAFE Micro Edition Suite versions prior to 4.1.6.3 (in 4.1.x) and prior to 4.4 (in 4.2.x and 4.3.x), are vulnerable to an Information Exposure Through an Error Message vulnerability, also known as a “padding oracle...Show more |
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the nam...Show more |
RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error cond...Show more |
1Microfocus 1Service Manager Jun 17, 2026 Sep 18, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited in some sp...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error messa...Show more |
Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users. |
1Silver Peak 1Unity Edgeconnect Sd Wan Firmware Jun 17, 2026 Sep 8, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI. |
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed...Show more |
1Bosch 2Iot Gateway Software Prosyst Mbs SdkJun 17, 2026 Aug 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structu...Show more |
1Ibm 3Emptoris Contract Management Emptoris SourcingEmptoris Spend AnalysisJun 17, 2026 Aug 20, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could...Show more |
1Ibm 3Emptoris Contract Management Emptoris SourcingEmptoris Spend AnalysisJun 17, 2026 Aug 20, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could...Show more |
1Ibm 3Intelligent Operations Center Intelligent Operations Center For Emergency ManagementWater Operations For WaternamicsJun 17, 2026 Aug 20, 2019 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive information that could aid in further attacks against the system. IBM X-Force ID: 162738. |
1Ibm 3Emptoris Contract Management Emptoris SourcingEmptoris Spend AnalysisJun 17, 2026 Aug 20, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from err...Show more |
4Canonical DebianOpenstack+1 more4Debian Linux NovaOpenstack+1 moreJun 17, 2026 Aug 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the un...Show more |
1Parseplatform 1Parse Server Jun 17, 2026 Jul 29, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 parse-server before 3.6.0 allows account enumeration. |
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the cur...Show more |